VDB
CVE-2024-2097
CVE-2024-2097
PUBLISHED
CVSS 7.5 HIGH
Authenticated List control client can execute the LINQ query in SCM Server to present event as list for operator. An authenticated malicious client can send special LINQ query to execute arbitrary code remotely (RCE) on the SCM Server that an attacker otherwise does not have authorization to do.
EPSS 0.46% · 38.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.46%
38.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| hitachienergy | modular_advanced_control_for_hvdc | 4.0, 4.0 |
| Hitachi Energy | MACH SCM Tools | 1.0, 1.0 |
| Hitachi Energy | MACH SCM Server | 4.0, 4.0 |
Timeline
- Mar 27, 2024 EPSS Score
- Mar 27, 2024 CVE Published
- Mar 27, 2024 CVE Updated
- Apr 22, 2024 EPSS Score
- May 18, 2024 EPSS Score
- Jun 12, 2024 EPSS Score
- Aug 7, 2024 EPSS Score
- Sep 2, 2024 EPSS Score
- Sep 27, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 23, 2024 EPSS Score
- Nov 18, 2024 EPSS Score