PatchSiren cyber security CVE debrief
CVE-2024-2377 Hitachi Energy CVE debrief
CVE-2024-2377 is a HIGH severity vulnerability (CVSS 7.6) in Hitachi Energy SDM600, published 2024-04-30. The issue stems from overly permissive HTTP response header configurations in the device's web server, which could allow an attacker to perform privileged actions and access sensitive information. The vulnerability affects SDM600 versions below 1.3.4. Hitachi Energy has released firmware version 1.3.4 (Build 1.3.4.574) to address this issue. The attack vector requires adjacent network access, high attack complexity, low privileges, and user interaction, with potential for high impact across confidentiality, integrity, and availability.
- Vendor
- Hitachi Energy
- Product
- SDM600
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-30
- Original CVE updated
- 2024-04-30
- Advisory published
- 2024-04-30
- Advisory updated
- 2024-04-30
Who should care
Organizations operating Hitachi Energy SDM600 devices in industrial environments, particularly those with web-based management interfaces exposed to internal networks. Critical infrastructure operators and energy sector entities utilizing SDM600 for monitoring and control applications should prioritize this patch.
Technical summary
The SDM600 device's web server is configured with overly permissive HTTP response headers, creating a security weakness that could be exploited by an attacker with adjacent network access and low privileges. Successful exploitation may enable the attacker to execute privileged operations and extract sensitive information from the device. The vulnerability requires user interaction and high attack complexity, but has severe potential impact with a scope change (S:C) indicating affected components beyond the vulnerable component. Remediation requires firmware update to version 1.3.4.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade SDM600 firmware to version 1.3.4 (Build 1.3.4.574) or later to remediate the overly permissive HTTP response header vulnerability.
- Review and harden HTTP security headers on SDM600 devices per vendor guidance and CISA ICS recommended practices.
- Implement network segmentation to limit adjacent network access to SDM600 management interfaces.
- Apply defense-in-depth strategies for industrial control systems as outlined in CISA guidance.
- Monitor SDM600 access logs for anomalous privileged actions or unauthorized sensitive information access attempts.
Evidence notes
Vulnerability confirmed via CISA CSAF advisory ICSA-24-354-02. Affected product identified as SDM600 versions below 1.3.4. Vendor fix available in version 1.3.4 (Build 1.3.4.574). CVSS vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H.
Official resources
-
CVE-2024-2377 CVE record
CVE.org
-
CVE-2024-2377 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-04-30