VDB

CVE-2024-2097

CVE-2024-2097 PUBLISHED CVSS 7.5 HIGH

Authenticated List control client can execute the LINQ query in SCM Server to present event as list for operator. An authenticated malicious client can send special LINQ query to execute arbitrary code remotely (RCE) on the SCM Server that an attacker otherwise does not have authorization to do.

EPSS 0.46% · 38.6th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.46%
38.6th percentile

Affected Products

VendorProductVersions
hitachienergymodular_advanced_control_for_hvdc4.0, 4.0
Hitachi EnergyMACH SCM Tools1.0, 1.0
Hitachi EnergyMACH SCM Server4.0, 4.0

Timeline

  • Mar 27, 2024 EPSS Score
  • Mar 27, 2024 CVE Published
  • Mar 27, 2024 CVE Updated
  • Apr 22, 2024 EPSS Score
  • May 18, 2024 EPSS Score
  • Jun 12, 2024 EPSS Score
  • Aug 7, 2024 EPSS Score
  • Sep 2, 2024 EPSS Score
  • Sep 27, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 23, 2024 EPSS Score
  • Nov 18, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›