PT-2024-33191 · Unknown · Microscada Pro/X Sys600

Published

2024-08-27

·

Updated

2025-05-15

·

CVE-2024-4872

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MicroSCADA Pro/X SYS600 (affected versions not specified)
Description A vulnerability exists in the query validation of the product. If exploited, this could allow an authenticated attacker to inject code towards persistent data. The product does not validate any query towards persistent data, resulting in a risk of injection attacks. Note that to successfully exploit this vulnerability, an attacker must have a valid credential.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2025-04967
CVE-2024-4872

Affected Products

Microscada Pro/X Sys600