// For flags

CVE-2024-2377

 

Severity Score

7.6
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

A vulnerability exists in the too permissive HTTP response header web server settings of the SDM600. An attacker can take advantage of this and possibly carry out privileged actions and access sensitive information.

Existe una vulnerabilidad en la configuraciĆ³n del servidor web del encabezado de respuesta HTTP demasiado permisiva del SDM600. Un atacante puede aprovechar esto y posiblemente realizar acciones privilegiadas y acceder a informaciĆ³n confidencial.

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-02-05 First Exploit
  • 2024-03-11 CVE Reserved
  • 2024-04-30 CVE Published
  • 2024-05-01 EPSS Updated
  • 2024-08-01 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-346: Origin Validation Error
CAPEC
  • CAPEC-234: Hijacking a privileged process
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hitachi Energy
Search vendor "Hitachi Energy"
SDM600
Search vendor "Hitachi Energy" for product "SDM600"
< 1.3.4
Search vendor "Hitachi Energy" for product "SDM600" and version " < 1.3.4"
en
Affected