Malicious Redirection Vulnerability
CVE-2024-7941

4.3MEDIUM

Key Information:

Vendor
Hitachi
Vendor
CVE Published:
27 August 2024

Summary

A vulnerability exists within the web application of Hitachi Energy products, where an HTTP parameter containing a URL may be exploited. An attacker can manipulate this parameter to redirect users to a malicious site. This redirection poses a significant risk as it can lead to phishing scams, ultimately enabling attackers to harvest user credentials and sensitive information unsuspecting users might enter. Proper validation and sanitization of URL parameters are crucial to mitigate these risks and protect users from potential attacks.

Affected Version(s)

MicroSCADA SYS600 10.0 <= 10.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.