Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MicroSCADA X SYS600 — Vulnerabilities & Security Advisories 12

All 12 CVE vulnerabilities found in MicroSCADA X SYS600, with AI-generated Chinese analysis, references, and POCs.

This page catalogs known vulnerabilities for the MicroSCADA X SYS600 product, focusing on weakness types associated with this vendor's industrial control system software. It aggregates security issues ranging from remote code execution and buffer overflows to improper access control and information disclosure flaws found within the specified hardware and software configurations. The collection includes both historical data and recent disclosures, covering a broad time range from initial product release through to the most recent advisory updates. Here, users can track the vendor's specific security advisories to stay informed about patches and workarounds, gain a deeper understanding of common weakness classes such as those defined by CWE that affect SCADA environments, and examine the complete vulnerability history of the MicroSCADA X SYS600 platform. This resource is designed to help security professionals, system administrators, and compliance officers assess risk profiles, verify remediation status, and understand the evolving threat landscape for this critical infrastructure component. By centralizing these details, the page facilitates informed decision-making regarding updates, segmentation strategies, and long-term maintenance planning. The information is structured to allow for efficient querying based on severity, release date, or specific technical attributes, ensuring that stakeholders can quickly locate relevant data without sifting through unrelated noise. This approach supports robust security hygiene and proactive risk management in operational technology settings.

Vendor: Hitachi Energy

CVE ID Title CVSS Severity Published
CVE-2025-39205 Hitachi MicroSCADA X SYS600 安全漏洞 CWE-295 6.5 Medium 2025-06-24
CVE-2025-39204 Hitachi MicroSCADA X SYS600 安全漏洞 CWE-200 6.5 Medium 2025-06-24
CVE-2025-39203 Hitachi Energy MicroSCADA X SYS600 安全漏洞 CWE-354 6.5 Medium 2025-06-24
CVE-2025-39202 Hitachi MicroSCADA X SYS600 安全漏洞 CWE-269 7.3 High 2025-06-24
CVE-2025-39201 Hitachi MicroSCADA X SYS600 安全漏洞 CWE-276 6.1 Medium 2025-06-24
CVE-2024-3980 Hitachi Energy MicroSCADA X SYS600 安全漏洞 CWE-22 8.8 High 2024-08-27
CVE-2024-4872 Hitachi Energy MicroSCADA X SYS600 安全漏洞 CWE-943 8.8 High 2024-08-27
CVE-2022-29492 A vulnerability exists in the handling of a malformed IEC 104 TCP packet. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TCP connection is left open. This may cause a denial-of-service if the affected conne ... CWE-20 5.3 Medium 2022-09-14
CVE-2022-1778 A vulnerability exists during the start of the affected SYS600, where an input validation flaw causes a buffer-overflow while reading a specific configuration file. Subsequently SYS600 will fail to start. The configuration file can only be accessed by ... CWE-119 7.5 High 2022-09-14
CVE-2022-29922 A vulnerability exists in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server. The vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS ... CWE-20 7.5 High 2022-09-14
CVE-2022-2277 A vulnerability exists in the ICCP stack of the affected SYS600 versions due to validation flaw in the process that establishes the ICCP communication. The validation flaw will cause a denial-of-service when ICCP of SYS600 is request to forward any da ... CWE-1284 7.5 High 2022-09-14
CVE-2022-29490 A vulnerability exists in the Workplace X WebUI in which an authenticated user is able to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. CWE-285 8.5 High 2022-09-12

All 12 known CVE vulnerabilities affecting MicroSCADA X SYS600 with full Chinese analysis, references, and POCs where available.