CVE-2024-0400 - CVE House
Back to Database
Status published High CVE-2024-0400

SCM Software is a client and server application. An Authenticated...

Vulnerability Description

SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An Authenticated malicious client can send a specially crafted code to skip the validation and execute arbitrary code (RCE) on the SCM Server remotely. Malicious clients can execute any command by using this RCE vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-0400

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Hitachi Energy

View all reports →

Affected Software

MACH SCM
Vulnerable Versions:
4.0

Timeline

Official Publish: March 27th, 2024
Last Modified: October 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)