An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.
2022-11-21T19:15:13.353
2024-11-21T07:19:25.587
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hitachienergy | microscada_pro_sys600 | 9.0 | Yes |
Application | hitachienergy | microscada_pro_sys600 | 9.1 | Yes |
Application | hitachienergy | microscada_pro_sys600 | 9.2 | Yes |
Application | hitachienergy | microscada_pro_sys600 | 9.3 | Yes |
Application | hitachienergy | microscada_pro_sys600 | 9.4 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10.1 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10.1.1 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10.2 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10.2.1 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10.3 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10.3.1 | Yes |
Application | hitachienergy | microscada_x_sys600 | 10.4 | Yes |