PT-2024-5839 · Hitachi · Hitachi Tuning Manager

Published

2024-08-05

·

Updated

2025-01-08

·

CVE-2024-5828

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hitachi Tuning Manager versions prior to 8.8.7-00
Description The issue is related to an Expression Language Injection vulnerability in Hitachi Tuning Manager, which allows code injection. This vulnerability can be exploited by a remote attacker to execute arbitrary code. The vulnerability is due to the lack of measures to neutralize special elements used in the expression language operator.
Recommendations For versions prior to 8.8.7-00, update to version 8.8.7-00 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable Expression Language Injection functionality until a patch is available.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-06584
CVE-2024-5828

Affected Products

Hitachi Tuning Manager