SB2025030541 - Improper validation of certificate with host mismatch in Hitachi Energy UNEM, ECST and XMC20
Published: March 5, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper validation of certificate with host mismatch (CVE-ID: CVE-2024-2462)
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to improper validation of certificate with host mismatch. An attacker with physical access can intercept or falsify data exchanges between the client and the server.
Remediation
Install update from vendor's website.