The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
History

Wed, 30 Oct 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy microscada Pro Sys600
Weaknesses CWE-88
CPEs cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_1:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf1:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf2:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf3:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf4:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf5:*:*:*:*:*:*
Vendors & Products Hitachienergy microscada Pro Sys600

Tue, 29 Oct 2024 13:45:00 +0000

Type Values Removed Values Added
Description The product allows user input to control or influence paths or file names that are used in filesystem operations, allowing the attacker to access or modify system files or other files that are critical to the application. The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Fri, 30 Aug 2024 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22

Wed, 28 Aug 2024 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy microscada X Sys600
CPEs cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*
Vendors & Products Hitachienergy microscada X Sys600

Wed, 28 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy
Hitachienergy microscada Sys600
CPEs cpe:2.3:a:hitachienergy:microscada_sys600:10.0:*:*:*:*:*:*:*
Vendors & Products Hitachienergy
Hitachienergy microscada Sys600
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 27 Aug 2024 13:00:00 +0000

Type Values Removed Values Added
Description The product allows user input to control or influence paths or file names that are used in filesystem operations, allowing the attacker to access or modify system files or other files that are critical to the application.
Weaknesses CWE-88
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published: 2024-08-27T12:42:41.124Z

Updated: 2024-10-29T13:35:30.374Z

Reserved: 2024-04-19T12:45:24.793Z

Link: CVE-2024-3980

cve-icon Vulnrichment

Updated: 2024-08-28T14:15:13.471Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-27T13:15:05.210

Modified: 2024-10-30T15:33:12.697

Link: CVE-2024-3980

cve-icon Redhat

No data.