SYS600 中存在一个漏洞:任何已对托管该应用程序的服务器操作系统进行身份验证的用户,在未通过 SYS600 系统自身身份验证的情况下,即可读取和修改应用程序对象。 只有 SYS600 系统的用户才应被允许查看和修改应用程序对象。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Hitachi Energy | MicroSCADA SYS600 | 10.0≤ 10.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Hitachi Energy | MicroSCADA SYS600 | 10.0 ~ 10.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9854 | 8.5 HIGH | SYS600 RBAC权限提升至Windows管理员漏洞 |
| CVE-2026-17539 | 5.9 MEDIUM | RTU500 IEC104空指针解引用导致拒绝服务 |
| CVE-2026-9852 | 4.6 MEDIUM | SYS600 CSV注入漏洞 |
No comments yet