Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-3980


The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.


Published

2024-08-27T13:15:05.210

Last Modified

2024-10-30T15:33:12.697

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.9 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hitachienergy microscada_pro_sys600 9.4 Yes
Application hitachienergy microscada_pro_sys600 9.4 Yes
Application hitachienergy microscada_pro_sys600 9.4 Yes
Application hitachienergy microscada_pro_sys600 9.4 Yes
Application hitachienergy microscada_pro_sys600 9.4 Yes
Application hitachienergy microscada_pro_sys600 9.4 Yes
Application hitachienergy microscada_x_sys600 < 10.6 Yes

References