VYPR
Vendor

Hitachienergy

Products
47
CVEs
105
Across products
166
Status
Private

Products

47
View all 47 products →

Recent CVEs

105
View all 105 CVEs →
  • CVE-2019-5620CriApr 29, 2020
    risk 0.72cvss 9.8epss 0.70

    ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.

  • CVE-2024-2013CriJun 11, 2024
    risk 0.65cvss 10.0epss 0.01

    An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the services and the post-authentication attack surface.

  • CVE-2019-18253CriNov 27, 2019
    risk 0.65cvss 10.0epss 0.02

    An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.

  • CVE-2024-4872CriAug 27, 2024
    risk 0.64cvss 9.9epss 0.01

    A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.

  • CVE-2024-3980CriAug 27, 2024
    risk 0.64cvss 9.9epss 0.01

    The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the…

  • CVE-2022-3682CriMar 28, 2023
    risk 0.64cvss 9.9epss 0.01

    A vulnerability exists in the SDM600 file permission validation. An attacker could exploit the vulnerability by gaining access to the system and uploading a specially crafted message to the system node, which could result in Arbitrary code Executing. This issue affects: All…

  • CVE-2018-14805CriAug 29, 2018
    risk 0.64cvss 9.8epss 0.05

    ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are present. Both conditions are required to exploit this vulnerability.

  • CVE-2024-2012CriJun 11, 2024
    risk 0.59cvss 9.1epss 0.01

    vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allowing sensitive data to be read or modified or could cause other unintended behavior

  • CVE-2021-40333CriDec 2, 2021
    risk 0.59cvss 9.0epss 0.01

    Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access to the Data Communication Network (DCN) routing configuration. This issue affects: Hitachi Energy FOX61x versions prior to R15A. Hitachi Energy XCM20 versions…

  • CVE-2022-3388HigNov 21, 2022
    risk 0.57cvss 8.8epss 0.00

    An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

  • CVE-2017-16731HigDec 20, 2017
    risk 0.57cvss 8.8epss 0.01

    An Unprotected Transport of Credentials issue was discovered in ABB Ellipse 8.3 through Ellipse 8.9 released prior to December 2017 (including Ellipse Select). A vulnerability exists in the authentication of Ellipse to LDAP/AD using the LDAP protocol. An attacker could exploit…

  • CVE-2024-2011HigJun 11, 2024
    risk 0.56cvss 8.6epss 0.00

    A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, which is usually outside the scope of a program's implicit security policy

  • CVE-2021-40334HigDec 2, 2021
    risk 0.56cvss 8.6epss 0.01

    Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 allows an attacker that exploits the vulnerability by activating SSH on port TCP 5558 to cause disruption to the NMS and NE communication. This issue affects:…

  • CVE-2022-29490HigSep 12, 2022
    risk 0.55cvss 8.5epss 0.01

    Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issue affects: Hitachi Energy MicroSCADA X…

  • CVE-2024-7940HigAug 27, 2024
    risk 0.54cvss 8.3epss 0.01

    The product exposes a service that is intended for local only to all network interfaces without any authentication.

  • CVE-2022-3929HigJan 5, 2023
    risk 0.54cvss 8.3epss 0.00

    Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This protocol is not encrypted and allows tracing of internal messages. This issue affects * …

  • CVE-2026-2460HigFeb 24, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.

  • CVE-2026-2459HigFeb 24, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.

  • CVE-2024-3982HigAug 27, 2024
    risk 0.53cvss 8.2epss 0.00

    An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users…

  • CVE-2021-35535HigNov 18, 2021
    risk 0.53cvss 8.1epss 0.01

    Insecure Boot Image vulnerability in Hitachi Energy Relion Relion 670/650/SAM600-IO series allows an attacker who manages to get access to the front network port and to cause a reboot sequences of the device may exploit the vulnerability, where there is a tiny time gap during…