CVE-2024-3982

An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-08-27 13:15

Updated : 2024-10-30 15:32


NVD link : CVE-2024-3982

Mitre link : CVE-2024-3982

CVE.ORG link : CVE-2024-3982


JSON object : View

Products Affected

hitachienergy

  • microscada_x_sys600
CWE
CWE-294

Authentication Bypass by Capture-replay