CVE-2024-4872
27.08.2024, 13:15
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.Enginsight
Vendor | Product | Version |
---|---|---|
hitachienergy | microscada_pro_sys600 | 9.4:fixpack_2_hf1 |
hitachienergy | microscada_pro_sys600 | 9.4:fixpack_2_hf2 |
hitachienergy | microscada_pro_sys600 | 9.4:fixpack_2_hf3 |
hitachienergy | microscada_pro_sys600 | 9.4:fixpack_2_hf4 |
hitachienergy | microscada_pro_sys600 | 9.4:fixpack_2_hf5 |
hitachienergy | microscada_x_sys600 | 10.0 ≤ 𝑥 < 10.6 |
𝑥
= Vulnerable software versions