Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Hitachi Energy — Vulnerabilities & Security Advisories 114

Browse all 114 CVE security advisories affecting Hitachi Energy. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Hitachi Energy operates as a global technology leader specializing in electrification products, grid automation, and renewable energy solutions. Its portfolio includes critical infrastructure components such as power transformers, high-voltage direct current systems, and digital grid management software, making it a vital node in global energy distribution. Security assessments reveal a historical prevalence of common vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation flaws, particularly within its industrial control software and web-based management interfaces. These weaknesses often stem from legacy codebases and complex integration requirements inherent in operational technology environments. While no catastrophic public breaches have been widely documented, the sheer volume of recorded CVEs indicates persistent challenges in patching distributed assets. The company maintains rigorous internal security protocols, yet the attack surface remains expansive due to the interconnected nature of modern smart grids and the long lifecycle of installed hardware.

CVE ID Title CVSS Severity Published
CVE-2022-3928 Hardcoded credential is found in the message queue — FOXMAN-UN CWE-798 7.1 High 2023-01-05
CVE-2022-3927 The affected products store public and private key that are used to sign and protect custom parameter set files from modification. — FOXMAN-UN CWE-798 8.0 High 2023-01-05
CVE-2021-40342 Use of default key for encryption — FOXMAN-UN CWE-798 7.1 High 2023-01-05
CVE-2021-40341 Weak DES encryption — FOXMAN-UN CWE-326 7.1 High 2023-01-05
CVE-2022-2513 Cleartext Credentials Vulnerability on Hitachi Energy’s Multiple IED Connectivity Packages (IED ConnPacks) and PCM600 Products — PCM600 CWE-312 7.1 High 2022-11-22
CVE-2022-3388 Input Validation Vulnerability in Hitachi Energy’s MicroSCADA Pro/X SYS600 Products — MicroSCADA Pro SYS600 CWE-20 8.8 High 2022-11-21
CVE-2022-29492 A vulnerability exists in the handling of a malformed IEC 104 TCP packet. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TCP connection is left open. This may cause a denial-of-service if the affected conne ... — MicroSCADA X SYS600 CWE-20 5.3 Medium 2022-09-14
CVE-2022-1778 A vulnerability exists during the start of the affected SYS600, where an input validation flaw causes a buffer-overflow while reading a specific configuration file. Subsequently SYS600 will fail to start. The configuration file can only be accessed by ... — MicroSCADA X SYS600 CWE-119 7.5 High 2022-09-14
CVE-2022-29922 A vulnerability exists in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server. The vulnerability may cause a denial-of-service on the IEC 61850 OPC Server part of the SYS ... — MicroSCADA X SYS600 CWE-20 7.5 High 2022-09-14
CVE-2022-2277 A vulnerability exists in the ICCP stack of the affected SYS600 versions due to validation flaw in the process that establishes the ICCP communication. The validation flaw will cause a denial-of-service when ICCP of SYS600 is request to forward any da ... — MicroSCADA X SYS600 CWE-1284 7.5 High 2022-09-14
CVE-2022-29490 A vulnerability exists in the Workplace X WebUI in which an authenticated user is able to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. — MicroSCADA X SYS600 CWE-285 8.5 High 2022-09-12
CVE-2021-40336 HTTP Response Splitting in Hitachi Energy’s MSM Product — MSM CWE-113 5.0 Medium 2022-07-25
CVE-2021-40335 Cross Site Request Forgery (CSRF) in Hitachi Energy’s MSM Product — MSM CWE-352 5.0 Medium 2022-07-25
CVE-2021-35530 User authentication bypass in TXpert Hub CoreTec 4 — TXpert Hub CoreTec 4 version CWE-288 6.0 Medium 2022-06-07
CVE-2021-35531 Remote Code Execution in TXpert Hub CoreTec 4 — TXpert Hub CoreTec 4 version CWE-20 6.7 - 2022-06-07
CVE-2021-35532 Firmware upload verification bypass in TXpert Hub CoreTec 4 — TXpert Hub CoreTec 4 version CWE-494 7.2 - 2022-06-07
CVE-2022-28613 Specially Crafted Modbus TCP Packet Vulnerability in RTU500 series — RTU500 series CMU Firmware CWE-1284 7.5 High 2022-05-02
CVE-2021-40337 OWASP Related Vulnerabilities in Hitachi Energy’s LinkOne Product — LinkOne CWE-79 4.2 Medium 2022-01-25
CVE-2021-40333 Weak default credential associated with TCP port 26 — FOX61x CWE-521 9.0 Critical 2021-12-02
CVE-2021-40334 SSH activation problem in the proprietary management protocol (port TCP 5558) — FOX61x CWE-431 8.6 High 2021-12-02
CVE-2021-35533 Specially Crafted IEC 60870-5-104 Packet Vulnerability in RTU500 series — RTU500 series CWE-20 7.5 High 2021-11-26
CVE-2021-35534 Insufficient Security Control Vulnerability — Relion 670 Series CWE-274 7.2 High 2021-11-18
CVE-2021-35535 Insufficient Security Control Vulnerability — Relion 670 Series CWE-1188 8.1 High 2021-11-18
CVE-2021-35528 Authentication Bypass Vulnerability Vulnerability in Retail Operations Product and Counterparty Settlement and Billing (CSB) — Retail Operations CWE-284 7.2 High 2021-11-17

This page lists every published CVE security advisory associated with Hitachi Energy. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.