Lucene search

K
cvelistHitachi EnergyCVELIST:CVE-2024-4872
HistoryAug 27, 2024 - 12:37 p.m.

CVE-2024-4872

2024-08-2712:37:28
CWE-943
Hitachi Energy
www.cve.org
4
product validation query injection persistent data risk attack

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

39.6%

The product does not validate any query towards persistent
data, resulting in a risk of injection attacks.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "MicroSCADA SYS600",
    "vendor": "Hitachi Energy",
    "versions": [
      {
        "lessThanOrEqual": "10.5",
        "status": "affected",
        "version": "10.0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

39.6%

Related for CVELIST:CVE-2024-4872