CVE-2022-3388
- EPSS 0.2%
- Veröffentlicht 21.11.2022 19:15:13
- Zuletzt bearbeitet 23.07.2025 21:15:25
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.
CVE-2022-29492
- EPSS 0.27%
- Veröffentlicht 14.09.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:59:11
Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro SYS600. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TC...
CVE-2022-29922
- EPSS 0.51%
- Veröffentlicht 14.09.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:59:58
Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro SYS600. The vuln...
CVE-2022-2277
- EPSS 0.13%
- Veröffentlicht 14.09.2022 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:40
Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment causes a denial-of-service when ICCP of SYS600 is request to forward any data item updates with timestam...
CVE-2022-1778
- EPSS 0.28%
- Veröffentlicht 14.09.2022 18:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:26
Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration file causes a buffer-overflow that causes a failure to start the SYS600. The configuration file can only be accessed by an administra...
CVE-2022-29490
- EPSS 0.34%
- Veröffentlicht 12.09.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 06:59:10
Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issue affects: ...