CVE-2023-2625 CRITICAL

CVE-2023-2625

Vendor Hitachi Energy
Product TXpert Hub CoreTec 4
Weakness CWE-78
Published June 28, 2023
Last update December 4, 2024

CVSS base score

9.0/10
Attack vector Adjacent
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN. To exploit the vulnerability the attacker can inject shell commands through a particular field of the web user interface that will be executed by the system.

Key dates

02Disclosure timeline

June 28, 2023 CVE published
December 4, 2024 Record updated