Back to overview

CVE-2024-3980

CRITICAL
9.9
CVSS 3.1
Description
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.

Metadata

CVE ID
CVE-2024-3980
State
PUBLISHED
Assigner
Hitachi Energy
Reserved
2024-04-19 12:45 UTC
Published
2024-08-27 12:42 UTC
Last updated
2025-08-27 21:24 UTC
Primary CWE
CWE-22
CWE-22 Improper Limitation of a Pathname to a Restricted Dir…
Vendor / Product
Hitachi Energy / MicroSCADA X SYS600
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
Hitachi Energy MicroSCADA Pro SYS600 9.4 FP2 HF1 ≤ 9.4 FP2 HF5, 9.4 FP1
Hitachi Energy MicroSCADA X SYS600 10.0 ≤ 10.5
Weakness (CWE)
CWESourceDescription
CWE-22 cna CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
8.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview