Authenticated List control client can execute the LINQ query in SCM Server to present event as list for operator. An authenticated malicious client can send special LINQ query to execute arbitrary code remotely (RCE) on the SCM Server that an attacker otherwise does not have authorization to do.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Hitachi Energy
Published: 2024-03-27T02:26:17.338Z
Updated: 2024-08-02T16:33:21.698Z
Reserved: 2024-03-01T15:56:00.646Z
Link: CVE-2024-2097
Vulnrichment
Updated: 2024-08-01T19:03:38.825Z
NVD
Status : Awaiting Analysis
Published: 2024-03-27T03:15:12.290
Modified: 2024-08-02T16:35:42.490
Link: CVE-2024-2097
Redhat
No data.