CVE-2024-0400: Hitachi Energy Mach Scm
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An Authenticated malicious client can send a specially crafted code to skip the validation and execute arbitrary code (RCE) on the SCM Server remotely. Malicious clients can execute any command by using this RCE vulnerability.
Affected products
- Hitachi Energy Mach Scm: from 4.0, up to and including 4.38
Published 2024-03-27. Last modified 2026-06-17.