PatchSiren cyber security CVE debrief
CVE-2024-2377 Hitachi Energy CVE debrief
CVE-2024-2377 is a HIGH severity vulnerability (CVSS 7.6) in Hitachi Energy SDM600, published 2024-04-30. The issue stems from overly permissive HTTP response header configurations in the device's web server, which could allow an attacker to perform privileged actions and access sensitive information. The vulnerability affects SDM600 versions below 1.3.4. Hitachi Energy has released firmware version 1.3.4 (Build 1.3.4.574) to address this issue. The attack vector requires adjacent network access, high attack complexity, low privileges, and user interaction, with potential for high impact across confidentiality, integrity, and availability.
- Vendor
- Hitachi Energy
- Product
- SDM600
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-30
- Original CVE updated
- 2024-04-30
- Advisory published
- 2024-04-30
- Advisory updated
- 2024-04-30
Who should care
Organizations operating Hitachi Energy SDM600 devices in industrial environments, particularly those with web-based management interfaces exposed to internal networks. Critical infrastructure operators and energy sector entities utilizing SDM600 for monitoring and control applications should prioritize this patch.
Technical summary
The SDM600 device's web server is configured with overly permissive HTTP response headers, creating a security weakness that could be exploited by an attacker with adjacent network access and low privileges. Successful exploitation may enable the attacker to execute privileged operations and extract sensitive information from the device. The vulnerability requires user interaction and high attack complexity, but has severe potential impact with a scope change (S:C) indicating affected components beyond the vulnerable component. Remediation requires firmware update to version 1.3.4.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade SDM600 firmware to version 1.3.4 (Build 1.3.4.574) or later to remediate the overly permissive HTTP response header vulnerability.
- Review and harden HTTP security headers on SDM600 devices per vendor guidance and CISA ICS recommended practices.
- Implement network segmentation to limit adjacent network access to SDM600 management interfaces.
- Apply defense-in-depth strategies for industrial control systems as outlined in CISA guidance.
- Monitor SDM600 access logs for anomalous privileged actions or unauthorized sensitive information access attempts.
Evidence notes
Vulnerability confirmed via CISA CSAF advisory ICSA-24-354-02. Affected product identified as SDM600 versions below 1.3.4. Vendor fix available in version 1.3.4 (Build 1.3.4.574). CVSS vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-2377 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-2377
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-2377 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-2377
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-354-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-354-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.