CVE-2024-2097: Hitachi Energy Mach Scm Server
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools.
Affected products
- Hitachi Energy Mach Scm Server: from 4.0, up to and including 4.38.3
- Hitachi Energy Mach Scm Tools: from 1.0, up to and including 1.8
- Hitachienergy Modular Advanced Control For Hvdc: from 4.0, up to and including 4.38
Published 2024-03-27. Last modified 2026-06-17.