// For flags

CVE-2022-3388

Input Validation Vulnerability in Hitachi Energy’s MicroSCADA Pro/X SYS600 Products

Severity Score

7.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA
Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

Existe una vulnerabilidad de validación de entrada en la interfaz Monitor Pro de MicroSCADA Pro y MicroSCADA X SYS600. Un usuario autenticado puede iniciar una ejecución remota de código a nivel de administrador independientemente de la función del usuario autenticado.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2022-09-30 CVE Reserved
  • 2022-11-21 CVE Published
  • 2024-08-03 CVE Updated
  • 2024-11-05 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-20: Improper Input Validation
CAPEC
  • CAPEC-23: File Content Injection
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hitachienergy
Search vendor "Hitachienergy"
Microscada Pro Sys600
Search vendor "Hitachienergy" for product "Microscada Pro Sys600"
9.0
Search vendor "Hitachienergy" for product "Microscada Pro Sys600" and version "9.0"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada Pro Sys600
Search vendor "Hitachienergy" for product "Microscada Pro Sys600"
9.1
Search vendor "Hitachienergy" for product "Microscada Pro Sys600" and version "9.1"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada Pro Sys600
Search vendor "Hitachienergy" for product "Microscada Pro Sys600"
9.2
Search vendor "Hitachienergy" for product "Microscada Pro Sys600" and version "9.2"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada Pro Sys600
Search vendor "Hitachienergy" for product "Microscada Pro Sys600"
9.3
Search vendor "Hitachienergy" for product "Microscada Pro Sys600" and version "9.3"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada Pro Sys600
Search vendor "Hitachienergy" for product "Microscada Pro Sys600"
9.4
Search vendor "Hitachienergy" for product "Microscada Pro Sys600" and version "9.4"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10.1
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10.1"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10.1.1
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10.1.1"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10.2
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10.2"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10.2.1
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10.2.1"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10.3
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10.3"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10.3.1
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10.3.1"
-
Affected
Hitachienergy
Search vendor "Hitachienergy"
Microscada X Sys600
Search vendor "Hitachienergy" for product "Microscada X Sys600"
10.4
Search vendor "Hitachienergy" for product "Microscada X Sys600" and version "10.4"
-
Affected