An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.
2022-11-21T19:15:13.353
2025-07-23T21:15:25.387
Modified
CVSSv3.1: 8.8 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | hitachienergy | microscada_pro_sys600 | 9.0 | Yes |
| Application | hitachienergy | microscada_pro_sys600 | 9.1 | Yes |
| Application | hitachienergy | microscada_pro_sys600 | 9.2 | Yes |
| Application | hitachienergy | microscada_pro_sys600 | 9.3 | Yes |
| Application | hitachienergy | microscada_pro_sys600 | 9.4 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10.1 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10.1.1 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10.2 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10.2.1 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10.3 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10.3.1 | Yes |
| Application | hitachienergy | microscada_x_sys600 | 10.4 | Yes |