PT-2024-38706 · Hitachi Energy · Microscada X Sys600

Published

2024-08-27

·

Updated

2024-10-30

·

CVE-2024-7941

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: No specific software or versions are mentioned in the provided descriptions.
Description: The issue allows an HTTP parameter to contain a URL value, which can cause the web application to redirect the request to the specified URL. An attacker can modify the URL value to a malicious site, potentially launching a phishing scam and stealing user credentials.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-7941

Affected Products

Microscada X Sys600