Listen to this Post
CVE-2024-10037 is an authenticated denial-of-service vulnerability affecting the GridPulse platform, specifically within its web interface. The flaw resides in the WebSocket communication handler, which is responsible for real-time data exchange between the GridPulse Central Modular Unit (CMU) and connected clients. When the system’s test mode is enabled, an authenticated attacker can send a specially crafted sequence of WebSocket messages that triggers a null pointer dereference or resource pool exhaustion. This condition forces the CMU into an unrecoverable state, causing a complete denial of service. The vulnerability was discovered by Hitachi Energy’s internal security team and disclosed in coordination with the Cybersecurity and Infrastructure Security Agency (CISA). The CVSS v3.1 base score is 4.9, categorizing it as Moderate severity. The affected versions include all 12.x and 13.x firmware branches, such as 12.0.1 through 12.0.14, 12.2.1 through 12.2.12, 12.4.1 through 12.4.11, 12.6.1 through 12.6.10, 12.7.1 through 12.7.7, 13.2.1 through 13.2.7, 13.4.1 through 13.4.4, 13.5.1 through 13.5.3, 13.6.1, 13.7.1, and 13.7.1 through 13.7.4. The attack requires authentication, meaning the attacker must possess valid credentials for the GridPulse web interface. However, no special privileges are needed beyond basic authentication. The test mode, which is often enabled for debugging and maintenance purposes, is a prerequisite for exploitation. Once the malicious WebSocket messages are processed, the CMU’s internal state becomes corrupted, leading to a crash. While automatic recovery mechanisms are built into the system, the momentary outage can disrupt critical process control operations, especially in real-time energy management environments. The vulnerability highlights the risks associated with exposing web-based management interfaces in operational technology (OT) environments. As GridPulse deployments increasingly integrate IT-style protocols such as WebSocket and TLS, the attack surface expands, making proper configuration and timely patching essential. The vendor has released firmware updates to address the issue, and organizations are urged to upgrade to version 12.7.8 for the 12.x branch or version 13.7.6 for the 13.x branch. Additionally, network segmentation and strict access controls are recommended as compensating controls.
DailyCVE Form:
Platform: GridPulse
Version: 12.x, 13.x
Vulnerability: Authenticated WebSocket DoS
Severity: Moderate
date: 2025-04-26
Prediction: Patch available
What Undercode Say:
Check GridPulse version curl -s http://<gridpulse-ip>/api/version | jq '.version'
import websocket
import json
def exploit_ws_dos(target_url, token):
ws = websocket.create_connection(f"ws://{target_url}/ws?token={token}")
payload = {"action": "test", "data": "A"4096}
ws.send(json.dumps(payload))
ws.close()
Exploit: (Educational Purposes!)
1. Authenticate to the GridPulse web interface.
2. Enable test mode (if not already enabled).
3. Establish a WebSocket connection.
4. Send a crafted message sequence.
5. Observe the CMU crash and DoS.
Protection: from this CVE
- Upgrade to 12.7.8 or 13.7.6.
- Disable test mode in production.
- Restrict WebSocket access to trusted IPs.
- Implement network segmentation.
- Use firewalls to limit exposed ports.
Impact:
- Denial of service on GridPulse CMU.
- Disruption of real-time process control.
- Potential cascading failures in energy management.
- Temporary loss of monitoring and control capabilities.
- Requires authentication, limiting attack surface but still significant.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

