Description
A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log.
Published: 2026-09-03
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CSV injection exists in MicroSCADA SYS600. Malicious formulas can modify spreadsheet content, insert links, exfiltrate data, and, in certain configurations, may allow code execution on the user’s machine. The vulnerability exploits the ability to add arbitrary log messages via SCIL scripts, log injection, or the broker, causing the spreadsheet to interpret user‑supplied formulas.

Affected Systems

All Windows users of Hitachi Energy MicroSCADA SYS600 are affected, regardless of privilege level, as long as they can run the Notify service and export the log. No specific version range is provided; the product as currently shipped is vulnerable.

Risk and Exploitability

The CVSS score of 4.6 indicates moderate risk. No EPSS score is available and the issue is not in the CISA KEV catalog, suggesting limited public exploitation. Exploitation requires the ability to create arbitrary log messages, which could be achieved through normal functionality or a separate log injection flaw. Attackers would need a configuration that executes user‑supplied formulas from exported logs, so risk is contingent on the environment. System administrators should treat the flaw as a moderate threat and monitor for unusual log or spreadsheet activity.

Generated by OpenCVE AI on September 3, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict or audit SCIL script execution to trusted users and enforce input validation to prevent arbitrary log messages.
  • Disable or restrict the Notify service export feature until a vendor update is available.
  • Monitor exported log files and spreadsheets for unexpected formulas or suspicious links and investigate anomalies promptly.

Generated by OpenCVE AI on September 3, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Title CSV Injection in Hitachi Energy MicroSCADA SYS600 Enabling Data Manipulation and Potential Code Execution
First Time appeared Hitachienergy
Hitachienergy microscada Sys600
Vendors & Products Hitachienergy
Hitachienergy microscada Sys600

Thu, 03 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a way to create arbitrary log messages. This could be achieved through normal functionality via SCIL scripts, a log injection vulnerability, or via the SYS600 broker. This vulnerability affects all Windows users regardless of their privilege level who can run the Notify service and export the log.
Weaknesses CWE-1236
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Hitachienergy Microscada Sys600
cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2026-09-03T12:49:40.825Z

Reserved: 2026-05-28T15:04:54.747Z

Link: CVE-2026-9852

cve-icon Vulnrichment

Updated: 2026-09-03T12:49:37.663Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T13:06:25.803

Modified: 2026-09-03T16:43:15.293

Link: CVE-2026-9852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T09:15:05Z

Weaknesses
  • CWE-1236

    Improper Neutralization of Formula Elements in a CSV File