CVE-2024-4872 is a high-severity vulnerability affecting Hitachi Energy MicroSCADA Pro/X SYS600 products, stemming from improper query validation that allows for code injection. An authenticated attacker can exploit this with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While the vulnerability has a CVSS score of 8.8 and a FAUCET Risk Score of 70/100, there is currently no public exploit code available, nor is it listed in CISA's KEV catalog. Despite limited community discussion and media coverage, organizations using affected products should prioritize patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.4CPE matchmatch criteria | cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf1:*:*:*:*:*:* | ||
9.4CPE matchmatch criteria | cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf2:*:*:*:*:*:* | ||
9.4CPE matchmatch criteria | cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf3:*:*:*:*:*:* | ||
9.4CPE matchmatch criteria | cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf4:*:*:*:*:*:* | ||
9.4CPE matchmatch criteria | cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:fixpack_2_hf5:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.