PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-2377 Hitachi Energy CVE debrief

CVE-2024-2377 is a HIGH severity vulnerability (CVSS 7.6) in Hitachi Energy SDM600, published 2024-04-30. The issue stems from overly permissive HTTP response header configurations in the device's web server, which could allow an attacker to perform privileged actions and access sensitive information. The vulnerability affects SDM600 versions below 1.3.4. Hitachi Energy has released firmware version 1.3.4 (Build 1.3.4.574) to address this issue. The attack vector requires adjacent network access, high attack complexity, low privileges, and user interaction, with potential for high impact across confidentiality, integrity, and availability.

Vendor
Hitachi Energy
Product
SDM600
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-30
Original CVE updated
2024-04-30
Advisory published
2024-04-30
Advisory updated
2024-04-30

Who should care

Organizations operating Hitachi Energy SDM600 devices in industrial environments, particularly those with web-based management interfaces exposed to internal networks. Critical infrastructure operators and energy sector entities utilizing SDM600 for monitoring and control applications should prioritize this patch.

Technical summary

The SDM600 device's web server is configured with overly permissive HTTP response headers, creating a security weakness that could be exploited by an attacker with adjacent network access and low privileges. Successful exploitation may enable the attacker to execute privileged operations and extract sensitive information from the device. The vulnerability requires user interaction and high attack complexity, but has severe potential impact with a scope change (S:C) indicating affected components beyond the vulnerable component. Remediation requires firmware update to version 1.3.4.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade SDM600 firmware to version 1.3.4 (Build 1.3.4.574) or later to remediate the overly permissive HTTP response header vulnerability.
  • Review and harden HTTP security headers on SDM600 devices per vendor guidance and CISA ICS recommended practices.
  • Implement network segmentation to limit adjacent network access to SDM600 management interfaces.
  • Apply defense-in-depth strategies for industrial control systems as outlined in CISA guidance.
  • Monitor SDM600 access logs for anomalous privileged actions or unauthorized sensitive information access attempts.

Evidence notes

Vulnerability confirmed via CISA CSAF advisory ICSA-24-354-02. Affected product identified as SDM600 versions below 1.3.4. Vendor fix available in version 1.3.4 (Build 1.3.4.574). CVSS vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-2377 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-2377

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-2377 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-2377

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-354-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-354-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.