VendorsHitachi Energysys600any version
Vulnerabilities

Hitachi Energy SYS600 any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2022-29490
A vulnerability exists in the Workplace X WebUI in which an authenticated user is able to execute any MicroSCADA internal scripts irrespective of the authenticated user's role.
Published 2022-09-12 · Modified
8.8EPSS 0.006
CVE-2018-1168
This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097.
Published 2018-02-21 · Modified
7.8EPSS 0.003
CVE-2022-3353
IEC 61850 MMS-Server Vulnerability in multiple Hitachi Energy Products
Published 2023-02-21 · Modified
7.5EPSS 0.011
CVE-2022-29922
A vulnerability exists in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server. The vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS ...
Published 2022-09-14 · Modified
7.5EPSS 0.008
CVE-2022-2277
A vulnerability exists in the ICCP stack of the affected SYS600 versions due to validation flaw in the process that establishes the ICCP communication. The validation flaw will cause a denial-of-service when ICCP of SYS600 is request to forward any da ...
Published 2022-09-14 · Modified
7.5EPSS 0.008
CVE-2022-29492
A vulnerability exists in the handling of a malformed IEC 104 TCP packet. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TCP connection is left open. This may cause a denial-of-service if the affected conne ...
Published 2022-09-14 · Modified
7.5EPSS 0.007
CVE-2022-1778
A vulnerability exists during the start of the affected SYS600, where an input validation flaw causes a buffer-overflow while reading a specific configuration file. Subsequently SYS600 will fail to start. The configuration file can only be accessed by ...
Published 2022-09-14 · Modified
7.5EPSS 0.005