Authenticated List control client can execute the LINQ query in SCM Server to present event as list for operator. An authenticated malicious client can send special LINQ query to execute arbitrary code remotely (RCE) on the SCM Server that an attacker otherwise does not have authorization to do.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published: 2024-03-27T02:26:17.338Z

Updated: 2024-08-02T16:33:21.698Z

Reserved: 2024-03-01T15:56:00.646Z

Link: CVE-2024-2097

cve-icon Vulnrichment

Updated: 2024-08-01T19:03:38.825Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-27T03:15:12.290

Modified: 2024-08-02T16:35:42.490

Link: CVE-2024-2097

cve-icon Redhat

No data.