8.2
CVE-2024-3982
- EPSS 0.05%
- Veröffentlicht 27.08.2024 13:15:05
- Zuletzt bearbeitet 30.10.2024 15:32:23
- Quelle cybersecurity@hitachienergy.co
- CVE-Watchlists
- Unerledigt
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hitachienergy ≫ Microscada X Sys600 Version >= 10.0 < 10.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.162 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
| cybersecurity@hitachienergy.com | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-294 Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).