CVE-2024-3982

HIGH

MicroSCADA X - Session Hijacking

Title source: llm
STIX 2.1

Description

An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.

Scores

CVSS v3 8.2
EPSS 0.0006
EPSS Percentile 18.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-294
Status published
Products (1)
hitachienergy/microscada_x_sys600 10.0 - 10.6
Published Aug 27, 2024
Tracked Since Feb 18, 2026