PT-2024-33191 · Unknown · Microscada Pro/X Sys600
Published
2024-08-27
·
Updated
2025-05-15
·
CVE-2024-4872
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MicroSCADA Pro/X SYS600 (affected versions not specified)
Description
A vulnerability exists in the query validation of the product. If exploited, this could allow an authenticated attacker to inject code towards persistent data. The product does not validate any query towards persistent data, resulting in a risk of injection attacks. Note that to successfully exploit this vulnerability, an attacker must have a valid credential.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microscada Pro/X Sys600