VYPR

Vendor CVEs

Hitachi

All CVEs

351 total · sorted by risk
  • CVE-2018-14735HigAug 9, 2018
    risk 0.49cvss 7.5epss 0.01

    An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of messaging that may allow for information exposure via a crafted message.

  • CVE-2008-2169HigMay 13, 2008
    risk 0.49cvss 7.5epss 0.01

    Unspecified vulnerability in Avici routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.

  • CVE-2024-28021HigJun 11, 2024
    risk 0.48cvss 7.4epss 0.00

    A vulnerability exists in the FOXMAN-UN/UNEM server that affects the message queueing mechanism’s certificate validation. If exploited an attacker could spoof a trusted entity causing a loss of confidentiality and integrity.

  • CVE-2023-1514HigDec 19, 2023
    risk 0.48cvss 7.4epss 0.00

    A vulnerability exists in the component RTU500 Scripting interface. When a client connects to a server using TLS, the server presents a certificate. This certificate links a public key to the identity of the service and is signed by a Certification Authority (CA), allowing the…

  • CVE-2025-39202HigJun 24, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.

  • CVE-2024-57964HigFeb 18, 2025
    risk 0.47cvss 7.3epss 0.00

    Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects HVAC Energy Saving Program:.

  • CVE-2024-57963HigFeb 18, 2025
    risk 0.47cvss 7.3epss 0.00

    Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on affected systems. This issue affects USB-CONVERTERCABLE DRIVER:.

  • CVE-2024-41153HigOct 29, 2024
    risk 0.47cvss 7.2epss 0.02

    Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive…

  • CVE-2024-2617HigApr 30, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature was not enabled on all CMUs of a RTU500. If a malicious actor successfully exploits this vulnerability, they could use it to update the…

  • CVE-2022-4146HigJul 18, 2023
    risk 0.47cvss 7.3epss 0.01

    Expression Language Injection vulnerability in Hitachi Replication Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Replication Manager: before 8.8.5-02.

  • CVE-2022-3884HigFeb 28, 2023
    risk 0.47cvss 7.3epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID Agent component) allows local users to read and write specific files.This issue affects Hitachi Ops Center Analyzer: from 10.9.0-00 before 10.9.0-01.

  • CVE-2022-34883HigSep 6, 2022
    risk 0.47cvss 7.2epss 0.01

    OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to execute arbitrary OS commands. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versions prior to 02.03.02 on Windows;…

  • CVE-2021-35534HigNov 18, 2021
    risk 0.47cvss 7.2epss 0.02

    Insufficient security control vulnerability in internal database access mechanism of Hitachi Energy Relion 670/650/SAM600-IO, Relion 650, GMS600, PWC600 allows attacker who successfully exploited this vulnerability, of which the product does not sufficiently restrict access to…

  • CVE-2021-35528HigNov 17, 2021
    risk 0.47cvss 7.2epss 0.00

    Improper Access Control vulnerability in the application authentication and authorization of Hitachi Energy Retail Operations, Counterparty Settlement and Billing (CSB) allows an attacker to execute a modified signed Java Applet JAR file. A successful exploitation may lead to…

  • CVE-2025-66445HigDec 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Authorization bypass vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component) and Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops Center…

  • CVE-2024-46899HigApr 22, 2025
    risk 0.46cvss 7.1epss 0.00

    Hitachi Ops Center Common Services within Hitachi Ops Center Analyzer viewpoint OVF contains an authentication credentials leakage vulnerability.This issue affects Hitachi Ops Center Common Services: from 10.0.0-00 before 11.0.0-04; Hitachi Ops Center Analyzer viewpoint OVF:…

  • CVE-2024-45068HigDec 3, 2024
    risk 0.46cvss 7.1epss 0.00

    Authentication credentials leakage vulnerability in Hitachi Ops Center Common Services within Hitachi Ops Center OVA. This issue affects Hitachi Ops Center Common Services: from 10.9.3-00 before 11.0.3-00; Hitachi Ops Center OVA: from 10.9.3-00 before 11.0.2-01.

  • CVE-2024-28982HigJun 26, 2024
    risk 0.46cvss 7.1epss 0.00

    Hitachi Vantara Pentaho Business Analytics Server versions before 10.1.0.0 and 9.3.0.7, including 8.3.x do not correctly protect the ACL service endpoint of the Pentaho User Console against XML External Entity Reference.

  • CVE-2022-43941HigApr 3, 2023
    risk 0.46cvss 7.1epss 0.01

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 

  • CVE-2022-3928HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Hardcoded credential is found in affected products' message queue. An attacker that manages to exploit this vulnerability will be able to access data to the internal message queue. This issue affects * FOXMAN-UN product: FOXMAN-UN R15B, FOXMAN-UN R15A, FOXMAN-UN R14B,…

  • CVE-2021-40342HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    In the DES implementation, the affected product versions use a default key for encryption. Successful exploitation allows an attacker to obtain sensitive information and gain access to the network elements that are managed by the affected products versions. This issue…

  • CVE-2021-40341HigJan 5, 2023
    risk 0.46cvss 7.1epss 0.00

    DES cipher, which has inadequate encryption strength, is used Hitachi Energy FOXMAN-UN to encrypt user credentials used to access the Network Elements. Successful exploitation allows sensitive information to be decrypted easily. This issue affects  * FOXMAN-UN product:…

  • CVE-2022-2513HigNov 22, 2022
    risk 0.46cvss 7.1epss 0.00

    A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600…

  • CVE-2021-45448HigNov 2, 2022
    risk 0.46cvss 7.1epss 0.01

    Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a service endpoint for templates which allows a user-supplied path to access resources that are out of bounds.  The software uses external input to construct a…

  • CVE-2021-31601HigNov 8, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of…

  • CVE-2021-29645HigOct 12, 2021
    risk 0.46cvss 7.0epss 0.00

    Hitachi JP1/IT Desktop Management 2 Agent 9 through 12 calls the SendMessageTimeoutW API with arbitrary arguments via a local pipe, leading to a local privilege escalation vulnerability. An attacker who exploits this issue could execute arbitrary code on the local system.

  • CVE-2026-8479MedMay 26, 2026
    risk 0.45cvss epss 0.00

    IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Service impact. Product is only affected if IEC 60870-5-104 functionality in…

  • CVE-2023-4816MedSep 11, 2023
    risk 0.45cvss 6.9epss 0.01

    A vulnerability exists in the Equipment Tag Out authentication, when configured with Single Sign-On (SSO) with password validation in T214. This vulnerability can be exploited by an authenticated user per-forming an Equipment Tag Out holder action (Accept, Release, and Clear)…

  • CVE-2025-24908MedApr 16, 2025
    risk 0.44cvss 6.8epss 0.00

    Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.…

  • CVE-2025-24907MedApr 16, 2025
    risk 0.44cvss 6.8epss 0.00

    Overview   The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.…

  • CVE-2024-5963MedAug 6, 2024
    risk 0.44cvss 6.7epss 0.00

    Unquoted Executable Path vulnerability in Hitachi Device Manager on Windows (Device Manager Server component).This issue affects Hitachi Device Manager: before 8.8.7-00.

  • CVE-2024-1532MedMar 27, 2024
    risk 0.44cvss 6.8epss 0.01

    A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being displayed as empty strings, if an authorized user uploads a specially crafted stb-language file.

  • CVE-2022-43771MedApr 3, 2023
    risk 0.44cvss 6.5epss 0.24

    Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x, using the Pentaho Data Access plugin exposes a service endpoint for CSV import which allows a user supplied path to access resources that are out of bounds.  

  • CVE-2021-35532MedJun 7, 2022
    risk 0.44cvss 6.7epss 0.00

    A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4 product. The vulnerability allows an attacker or malicious agent who manages to gain access to the system and obtain an account with sufficient privilege to upload a malicious…

  • CVE-2021-35531MedJun 7, 2022
    risk 0.44cvss 6.7epss 0.00

    Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights to inject an OS command that is executed by the system.…

  • CVE-2023-6457MedJan 16, 2024
    risk 0.43cvss 6.6epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-04.

  • CVE-2020-36695MedJul 18, 2023
    risk 0.43cvss 6.6epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager…

  • CVE-2020-36652MedFeb 28, 2023
    risk 0.43cvss 6.6epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center…

  • CVE-2020-36611MedJan 17, 2023
    risk 0.43cvss 6.6epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS, Hitachi Tuning Manager - Agent for SAN Switch components) allows local users to read…

  • CVE-2022-3191MedNov 1, 2022
    risk 0.43cvss 6.6epss 0.00

    Insertion of Sensitive Information into Log File vulnerability in Hitachi Ops Center Analyzer on Linux (Virtual Strage Software Agent component) allows local users to gain sensitive information. This issue affects Hitachi Ops Center Analyzer: from 10.8.1-00 before 10.9.0-00

  • CVE-2020-36605MedNov 1, 2022
    risk 0.43cvss 6.6epss 0.00

    Incorrect Default Permissions vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Analyzer probe component), Hitachi Ops Center Viewpoint on Linux (Viewpoint RAID Agent component) allows local…

  • CVE-2025-39205MedJun 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

  • CVE-2025-39204MedJun 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.

  • CVE-2025-39203MedJun 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop.

  • CVE-2025-1718MedJun 24, 2025
    risk 0.42cvss 6.5epss 0.00

    An authenticated user with file access privilege via FTP access can cause the Relion 670/650 and SAM600-IO series device to reboot due to improper disk space management.

  • CVE-2025-1531MedMay 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Authentication credentials leakage vulnerability in Hitachi Ops Center Analyzer viewpoint.This issue affects Hitachi Ops Center Analyzer viewpoint: from 10.0.0-00 before 11.0.4-00.

  • CVE-2025-1245MedMay 16, 2025
    risk 0.42cvss 6.5epss 0.00

    Bypass Connection Restriction vulnerability in Hitachi Infrastructure Analytics Advisor (Data Center Analytics component), Hitachi Ops Center Analyzer  (Hitachi Ops Center Analyzer detail view component).This issue affects Hitachi Infrastructure Analytics Advisor:; Hitachi Ops…

  • CVE-2025-27631MedMar 25, 2025
    risk 0.42cvss 6.5epss 0.00

    The TRMTracker web application is vulnerable to LDAP injection attack potentially allowing an attacker to inject code into a query and execute remote commands that can read and update data on the website.

  • CVE-2024-12169MedMar 25, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This vulnerability only applies, if secure communication using IEC 62351-3…

  • CVE-2024-6697MedFeb 20, 2025
    risk 0.42cvss 6.5epss 0.00

    The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. (CWE-280)   …

Page 3 of 8