Impact
CSV injection exists in MicroSCADA SYS600. Malicious formulas can modify spreadsheet content, insert links, exfiltrate data, and, in certain configurations, may allow code execution on the user’s machine. The vulnerability exploits the ability to add arbitrary log messages via SCIL scripts, log injection, or the broker, causing the spreadsheet to interpret user‑supplied formulas.
Affected Systems
All Windows users of Hitachi Energy MicroSCADA SYS600 are affected, regardless of privilege level, as long as they can run the Notify service and export the log. No specific version range is provided; the product as currently shipped is vulnerable.
Risk and Exploitability
The CVSS score of 4.6 indicates moderate risk. No EPSS score is available and the issue is not in the CISA KEV catalog, suggesting limited public exploitation. Exploitation requires the ability to create arbitrary log messages, which could be achieved through normal functionality or a separate log injection flaw. Attackers would need a configuration that executes user‑supplied formulas from exported logs, so risk is contingent on the environment. System administrators should treat the flaw as a moderate threat and monitor for unusual log or spreadsheet activity.
OpenCVE Enrichment