Impact
The flaw in MicroSCADA SYS600 allows any user who has authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. This bypass of internal authentication controls falls under CWE‑303 and enables an attacker to alter critical configuration or operational data, potentially compromising the integrity of the system and enabling further exploitation.
Affected Systems
Hitachi Energy MicroSCADA SYS600 is the affected product. The CVE does not specify particular versions, implying that any instance of this application where OS‑level users have been granted access is vulnerable. Only users authenticated to the server’s operating system have the capability to abuse this issue; users authenticated directly to SYS600 are not affected.
Risk and Exploitability
With a CVSS score of 8.5 the vulnerability is considered high severity, and the EPSS score is not available, but the lack of a KEV listing indicates that it is not currently known to be widely exploited. The attack vector is inferred to be local or remote OS access, where an attacker with any credential that grants OS‑level login privileges—such as SSH or local console—can exploit the flaw. No patch or workaround has been reported, so the risk remains significant until a vendor resolution is released.
OpenCVE Enrichment