Vulnerabilidades em Hitachi Energy

106 resultados
Análise Vexday

O portfólio de vulnerabilidades da Hitachi Energy apresenta um perfil de risco contido em termos de exploração ativa: nenhuma CVE consta no catálogo KEV da CISA, taxa abaixo da média geral do catálogo, e o EPSS mais elevado registrado — atribuído à CVE-2021-35534 — é de 0,0167, valor consideravelmente baixo. Das 105 CVEs catalogadas, 8 são classificadas como críticas e nenhuma possui prova de conceito pública disponível, o que reduz o risco de exploração oportunista imediata. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), padrão que historicamente serve de vetor para injeções e manipulação de dados em sistemas de controle industrial, merecendo atenção em revisões de código e hardening de interfaces. A chegada de 2 novas CVEs nos últimos 90 dias indica atividade de descoberta em andamento, justificando monitoramento contínuo mesmo diante do baixo nível de exploração observado.

CVE-2024-0400HIGHSCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customEPSS 0.6%CVE-2021-35535HIGHInsufficient Security Control VulnerabilityEPSS 0.6%CVE-2022-3684HIGHSDM600 endpoint vulnerability EPSS 0.6%CVE-2024-3980CRITICALThe MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystEPSS 0.6%CVE-2024-2012CRITICALvulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or codEPSS 0.6%CVE-2024-7940HIGHThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.6%CVE-2022-3927HIGHThe affected products store public and private key that are used to sign and protect custom parameter set files from modification.EPSS 0.6%CVE-2024-1532MEDIUMA vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor couEPSS 0.6%CVE-2022-29490HIGHA vulnerability exists in the Workplace X WebUI in which an authenticated user is able to execute any MicroSCADA internal scripts irrespective of the authenticated user's role.EPSS 0.6%CVE-2023-4816MEDIUMA vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. EPSS 0.5%CVE-2024-2461MEDIUMIf exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccessibleEPSS 0.5%CVE-2024-4872CRITICALA vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attackEPSS 0.5%CVE-2023-2621MEDIUM The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer systEPSS 0.5%CVE-2022-3683HIGHSDM600 API web services authorization validationEPSS 0.5%CVE-2023-2625CRITICALA vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, haviEPSS 0.5%CVE-2024-2011HIGHA heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but canEPSS 0.5%CVE-2021-40336MEDIUMHTTP Response Splitting in Hitachi Energy’s MSM ProductEPSS 0.5%CVE-2024-2097HIGHAn authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List controlEPSS 0.5%CVE-2024-1531HIGHA vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor couEPSS 0.4%CVE-2022-1778HIGHA vulnerability exists during the start of the affected SYS600, where an input validation flaw causes a buffer-overflow while reading a specific configuration file. Subsequently SYS600 will fail to start. The configuration file can only be accessed by ...EPSS 0.4%