SYS600 存在 CSV 注入漏洞。通过注入的恶意公式,攻击者可以向电子表格中添加或修改数据、插入链接、窃取数据,并且在某些情况下(取决于用户的系统配置),还可能在用户机器上执行恶意代码。要利用该漏洞,攻击者需要能够创建任意日志消息的方式。这可以通过 SCIL 脚本的正常功能、日志注入漏洞或 SYS600 中间件(broker)实现。该漏洞影响所有能够运行 Notify 服务并导出日志的 Windows 用户,无论其权限级别如何。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hitachi Energy | MicroSCADA SYS600 | 10.0≤ 10.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hitachi Energy | MicroSCADA SYS600 | 10.0 ~ 10.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9854 | 8.5 HIGH | SYS600 RBAC权限提升至Windows管理员漏洞 |
| CVE-2026-9853 | 8.5 HIGH | SYS600 认证缺失致对象越权读写漏洞 |
| CVE-2026-17539 | 5.9 MEDIUM | RTU500 IEC104空指针解引用导致拒绝服务 |
No comments yet