CVE-2024-9928
Estado: AplazadaMedia (5.3)—
A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could cause account takeover and unauthorized access to the system when an attacker conducts brute-force attacks against the equipment login. Note that the system supports only one concurrent session and implements a delay of more than a second between failed login attempts making it difficult to automate the attacks.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 31
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-307
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-9928",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-9928",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-11-26T15:22:53.166662Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@hitachienergy.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cybersecurity@hitachienergy.com",
"affectedData": [
{
"vendor": "Hitachi Energy",
"product": "NSD570 Teleprotection Equipment",
"versions": [
{
"status": "affected",
"version": "1.0",
"versionType": "custom",
"lessThanOrEqual": "1.20"
}
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:o:hitachienergy:nsd570_firmware:*:*:*:*:*:*:*:*"
],
"vendor": "hitachienergy",
"product": "nsd570_firmware",
"versions": [
{
"status": "affected",
"version": "1.0",
"versionType": "custom",
"lessThanOrEqual": "1.20"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2024-11-26T14:15:22.777",
"references": [
{
"url": "https://publisher.hitachienergy.com/preview?DocumentID=8DBD000173&LanguageCode=en&DocumentPartId=&Action=launch",
"source": "cybersecurity@hitachienergy.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@hitachienergy.com",
"description": [
{
"lang": "en",
"value": "CWE-307"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability exists in NSD570 login panel that does not restrict excessive authentication attempts. If exploited, this could\ncause account takeover and unauthorized access to the system\nwhen an attacker conducts brute-force attacks against the\nequipment login. Note that the system supports only one concurrent session and implements a delay of more than a second\nbetween failed login attempts making it difficult to automate the\nattacks."
},
{
"lang": "es",
"value": "Existe una vulnerabilidad en el panel de inicio de sesión de NSD570 que no restringe los intentos de autenticación excesivos. Si se explota, esto podría provocar la apropiación de cuentas y el acceso no autorizado al sistema cuando un atacante realiza ataques de fuerza bruta contra el inicio de sesión del equipo. Tenga en cuenta que el sistema solo admite una sesión simultánea e implementa un retraso de más de un segundo entre los intentos de inicio de sesión fallidos, lo que dificulta la automatización de los ataques."
}
],
"lastModified": "2026-06-17T08:25:31.943",
"sourceIdentifier": "cybersecurity@hitachienergy.com"
}