CVE-2024-4872: Critical severity hitachi energy microscada pro sys600 vulnerability
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4872?
CVE-2024-4872 is considered a critical vulnerability due to the potential for authenticated attackers to inject code.
How do I fix CVE-2024-4872?
To fix CVE-2024-4872, ensure you have applied the latest security patches provided for the affected versions of MicroSCADA Pro/SYS600.
What products are affected by CVE-2024-4872?
CVE-2024-4872 affects specific versions of Hitachienergy MicroSCADA Pro/SYS600 including 9.4 fixpack 2 and higher.
Can unauthenticated users exploit CVE-2024-4872?
No, CVE-2024-4872 requires an attacker to have valid credentials to exploit the vulnerability.
What is the impact of exploiting CVE-2024-4872?
Exploiting CVE-2024-4872 could allow an authenticated attacker to modify persistent data through code injection.