Lucene search

K
cve[email protected]CVE-2024-2617
HistoryApr 30, 2024 - 1:15 p.m.

CVE-2024-2617

2024-04-3013:15:47
web.nvd.nist.gov
31
vulnerability
rtu500
authenticated users
bypass
secure update
unsigned firmware
exploit

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update. If a
malicious actor successfully exploits this vulnerability, they
could use it to update the RTU500 with unsigned firmware.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "RTU500 series CMU firmware",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "lessThanOrEqual": "13.2.7",
        "status": "affected",
        "version": "13.2.1",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "13.4.4",
        "status": "affected",
        "version": "13.4.1",
        "versionType": "custom"
      },
      {
        "lessThanOrEqual": "13.5.3",
        "status": "affected",
        "version": "13.5.1",
        "versionType": "custom"
      }
    ]
  }
]

7.2 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.1%

Related for CVE-2024-2617