Description
A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.

Only the SYS600 system users should be permitted to view and modify application objects.
Published: 2026-09-03
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in MicroSCADA SYS600 allows any user who has authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. This bypass of internal authentication controls falls under CWE‑303 and enables an attacker to alter critical configuration or operational data, potentially compromising the integrity of the system and enabling further exploitation.

Affected Systems

Hitachi Energy MicroSCADA SYS600 is the affected product. The CVE does not specify particular versions, implying that any instance of this application where OS‑level users have been granted access is vulnerable. Only users authenticated to the server’s operating system have the capability to abuse this issue; users authenticated directly to SYS600 are not affected.

Risk and Exploitability

With a CVSS score of 8.5 the vulnerability is considered high severity, and the EPSS score is not available, but the lack of a KEV listing indicates that it is not currently known to be widely exploited. The attack vector is inferred to be local or remote OS access, where an attacker with any credential that grants OS‑level login privileges—such as SSH or local console—can exploit the flaw. No patch or workaround has been reported, so the risk remains significant until a vendor resolution is released.

Generated by OpenCVE AI on September 3, 2026 at 09:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Enforce strict OS‑level account management, limiting access to only users who must run the SYS600 application and removing unnecessary accounts.
  • Configure SYS600 to enforce authentication for all access to application objects; consider implementing a separate service user with limited privileges if the application supports it.
  • If a vendor patch or update is available, apply it immediately; otherwise, monitor the system for unauthorized configuration changes and log all object modifications for forensic analysis.

Generated by OpenCVE AI on September 3, 2026 at 09:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title OS‑Level Access Allows Unauthorized Modification of SYS600 Objects

Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy
Hitachienergy microscada Sys600
Vendors & Products Hitachienergy
Hitachienergy microscada Sys600

Thu, 03 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.
Weaknesses CWE-303
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Hitachienergy Microscada Sys600
cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published:

Updated: 2026-09-03T12:49:23.783Z

Reserved: 2026-05-28T15:04:56.583Z

Link: CVE-2026-9853

cve-icon Vulnrichment

Updated: 2026-09-03T12:49:20.468Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T13:06:25.943

Modified: 2026-09-03T16:43:15.293

Link: CVE-2026-9853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T09:45:03Z

Weaknesses
  • CWE-303

    Incorrect Implementation of Authentication Algorithm