Authenticated Remote Code Execution Vulnerability Affects SCM Server
CVE-2024-0400

7.7HIGH

Key Information:

Vendor

Hitachi

Status
Vendor
CVE Published:
27 March 2024

What is CVE-2024-0400?

SCM Software, developed by Hitachi Energy, is designed for both client and server applications. This vulnerability allows an authenticated system manager client to execute LINQ queries on the SCM server for customized filtering. However, a malicious authenticated client can exploit this functionality by sending specially crafted input that bypasses validation checks, enabling the remote execution of arbitrary code on the SCM server. This instance of remote code execution (RCE) poses a significant risk, as it grants attackers the ability to execute any command on the server, potentially compromising the entire system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MACH SCM 4.0 <= 4.38

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.