SDM600 file permission validation
CVE-2022-3682

9.9CRITICAL

Key Information:

Vendor
Hitachi
Status
Vendor
CVE Published:
28 March 2023

Summary

A vulnerability in the Hitachi Energy SDM600 product exists due to inadequate file permission validation. Attackers can exploit this flaw by uploading specially crafted messages to the system, potentially leading to arbitrary code execution. This issue can affect all versions of SDM600 prior to the secured revision 1.2 FP3 HF4 (Build Nr. 1.2.23000.291). Users are advised to update to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

SDM600 SDM600 1.2

SDM600 SDM600 1.1

SDM600 SDM600 1.0;

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.