Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-3388


An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.


Published

2022-11-21T19:15:13.353

Last Modified

2024-11-21T07:19:25.587

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hitachienergy microscada_pro_sys600 9.0 Yes
Application hitachienergy microscada_pro_sys600 9.1 Yes
Application hitachienergy microscada_pro_sys600 9.2 Yes
Application hitachienergy microscada_pro_sys600 9.3 Yes
Application hitachienergy microscada_pro_sys600 9.4 Yes
Application hitachienergy microscada_x_sys600 10 Yes
Application hitachienergy microscada_x_sys600 10.1 Yes
Application hitachienergy microscada_x_sys600 10.1.1 Yes
Application hitachienergy microscada_x_sys600 10.2 Yes
Application hitachienergy microscada_x_sys600 10.2.1 Yes
Application hitachienergy microscada_x_sys600 10.3 Yes
Application hitachienergy microscada_x_sys600 10.3.1 Yes
Application hitachienergy microscada_x_sys600 10.4 Yes

References