Cross-Site WebSocket Hijacking Vulnerability in Hitachi Ops Center Analyzer
CVE-2024-8201

5.4MEDIUM

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
16 May 2025

What is CVE-2024-8201?

A cross-site WebSocket hijacking vulnerability has been identified in the Hitachi Ops Center Analyzer, specifically in its RAID Agent component. This vulnerability allows an attacker to impersonate a user and manipulate WebSocket connections, potentially leading to unauthorized access or control over the affected application. The issue is present in versions of Hitachi Ops Center Analyzer ranging from 10.8.0-00 to 11.0.4-00 and from 10.9.0-00 to 11.0.4-00. Users are urged to implement patches and updates as provided by the vendor to mitigate this risk.

Affected Version(s)

Hitachi Ops Center Analyzer Linux 10.8.0-00 < 11.0.4-00

Hitachi Ops Center Analyzer Windows 10.9.0-00 < 11.0.4-00

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-8201 : Cross-Site WebSocket Hijacking Vulnerability in Hitachi Ops Center Analyzer