CVE-2024-9928

MEDIUM

NSD570 - DoS

Title source: llm
STIX 2.1

Description

A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (1)
Hitachi Energy/NSD570 Teleprotection Equipment 1.0 - 1.20
Published Nov 26, 2024
Tracked Since Feb 18, 2026