VYPR
Critical severity9.9NVD Advisory· Published Aug 27, 2024· Updated Jun 17, 2026

CVE-2024-4872

CVE-2024-4872

Description

A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.

Affected products

9
  • cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf1:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf1:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf2:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf3:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf4:*:*:*:*:*:*
    • cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf5:*:*:*:*:*:*
  • cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*range: >=10.0,<10.6
    • (no CPE)
  • Hitachi/MicroSCADA X SYS600cpe-rescue2 versions
    9.4 FP2 HF1+ 1 more
    • (no CPE)range: 9.4 FP2 HF1
    • (no CPE)range: 10.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.