An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
2024-08-27T13:15:05.557
2024-10-30T15:32:23.680
Analyzed
CVSSv3.1: 8.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | hitachienergy | microscada_x_sys600 | < 10.6 | Yes |