an attacker must have a valid credential.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-44446 | A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential. |
Wed, 30 Oct 2024 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachienergy microscada Pro Sys600
|
|
| Weaknesses | CWE-89 | NVD-CWE-Other |
| CPEs | cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf1:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf2:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf3:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf4:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf5:*:*:*:*:*:* |
|
| Vendors & Products |
Hitachienergy microscada Pro Sys600
|
Tue, 29 Oct 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The product does not validate any query towards persistent data, resulting in a risk of injection attacks. | A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential. |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 05 Sep 2024 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-943 |
Wed, 28 Aug 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachienergy microscada X Sys600
|
|
| CPEs | cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hitachienergy microscada X Sys600
|
Tue, 27 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachienergy
Hitachienergy microscada Sys600 |
|
| CPEs | cpe:2.3:a:hitachienergy:microscada_sys600:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hitachienergy
Hitachienergy microscada Sys600 |
|
| Metrics |
ssvc
|
Tue, 27 Aug 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The product does not validate any query towards persistent data, resulting in a risk of injection attacks. | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Hitachi Energy
Published:
Updated: 2025-08-27T21:30:14.068Z
Reserved: 2024-05-14T14:41:23.177Z
Link: CVE-2024-4872
Updated: 2024-08-27T13:46:43.106Z
Status : Analyzed
Published: 2024-08-27T13:15:05.890
Modified: 2024-10-30T15:31:41.743
Link: CVE-2024-4872
No data.
OpenCVE Enrichment
No data.
EUVD