CVE-2022-3388



An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA
Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.





ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Hitachi EnergyCNA
8.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 41%
VendorProductVersion
hitachienergymicroscada_pro_sys600
9.0
hitachienergymicroscada_pro_sys600
9.1
hitachienergymicroscada_pro_sys600
9.2
hitachienergymicroscada_pro_sys600
9.3
hitachienergymicroscada_pro_sys600
9.4
hitachienergymicroscada_x_sys600
10.1
hitachienergymicroscada_x_sys600
10.1.1
hitachienergymicroscada_x_sys600
10.2
hitachienergymicroscada_x_sys600
10.2.1
hitachienergymicroscada_x_sys600
10.3
hitachienergymicroscada_x_sys600
10.3.1
hitachienergymicroscada_x_sys600
10.4
𝑥
= Vulnerable software versions