CVE-2024-2097
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: cybersecurity@hitachienergy.com (Secondary)
Description
An authenticated malicious client can send a special LINQ query
to execute arbitrary code remotely (RCE) on the SCM server
from List control, and execute the arbitrary code on the same
system where SCMArchivedEventViewerTool is installed in the
case of SCM Tools.
References (2)
Source: cybersecurity@hitachienergy.com
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.