CVE-2022-3388
21.11.2022, 19:15
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.Enginsight
Vendor | Product | Version |
---|---|---|
hitachienergy | microscada_pro_sys600 | 9.0 |
hitachienergy | microscada_pro_sys600 | 9.1 |
hitachienergy | microscada_pro_sys600 | 9.2 |
hitachienergy | microscada_pro_sys600 | 9.3 |
hitachienergy | microscada_pro_sys600 | 9.4 |
hitachienergy | microscada_x_sys600 | 10.1 |
hitachienergy | microscada_x_sys600 | 10.1.1 |
hitachienergy | microscada_x_sys600 | 10.2 |
hitachienergy | microscada_x_sys600 | 10.2.1 |
hitachienergy | microscada_x_sys600 | 10.3 |
hitachienergy | microscada_x_sys600 | 10.3.1 |
hitachienergy | microscada_x_sys600 | 10.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration