Improper validation of certificate with host mismatch in Hitachi Energy products - CVE-2024-2462

 

Improper validation of certificate with host mismatch in Hitachi Energy products - CVE-2024-2462

Published: March 5, 2025


Vulnerability identifier: #VU105349
CSH Severity: Low
CVSS v4: 5.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-2462
CWE-ID: CWE-297
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to improper validation of certificate with host mismatch. An attacker with physical access can intercept or falsify data exchanges between the client and the server.


Affected software

UNEM
ECST
XMC20

How to mitigate CVE-2024-2462

Install updates from vendor's website.

UNEM - addressed in versions R15B PC5, R16B PC3
XMC20 - update to R16B
ECST - update to 16.2.1

External References

Related Security Bulletins