← Vulnerability feed

Vulnerability record · CVE-2019-5620 · published 29 April 2020

CVE-2019-5620: ABB MicroSCADA Pro SYS600 Missing Authentication for Critical Function

Hitachienergy · Microscada Pro Sys600

ABB MicroSCADA Pro SYS600 version 9.3 contains a missing authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can reach that function over the network, which matters because the product is used in SCADA/industrial control environments.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 7.5
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network-reachable, unauthenticated access to a critical function in a SCADA product, plus very high EPSS, makes this a top remediation priority.

What it is

ABB MicroSCADA Pro SYS600 version 9.3 contains a missing authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can reach that function over the network, which matters because the product is used in SCADA/industrial control environments.

Impact

An attacker gains full compromise of confidentiality, integrity and availability of the affected system, with CVSS 3.1 scoring 9.8. In a SCADA context this can translate into control over the process or host.

Attack surface

The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the flaw is reachable over the network with no authentication and no user interaction. The description does not identify the specific endpoint or service, only that a critical function lacks authentication.

Exploitation

Not listed in CISA KEV, but EPSS is 0.70081 (99.3rd percentile), indicating a high modeled likelihood of exploitation. A Rapid7 Metasploit module reference (abb_wserver_exec) exists, though the record does not state whether it has been used in the wild.

What to do

  • Apply the vendor fix for ABB MicroSCADA Pro SYS600 9.3; if no patch is available, isolate affected systems.
  • Restrict network access to SYS600 hosts with firewall rules and segmentation so only trusted management networks can reach them.
  • Place SYS600 behind a hardened jump host or VPN requiring authentication for any administrative or service access.
  • Monitor vendor advisories for updated fixed versions and upgrade as soon as they are released.
  • Disable or block any unnecessary services and ports on SYS600 hosts that are not required for operations.

Detection

  • Monitor network traffic to SYS600 hosts for unexpected connections to service ports from untrusted sources.
  • Alert on authentication-free access attempts or anomalous process execution on SYS600 systems.
  • Use the Rapid7 Metasploit module name abb_wserver_exec as a signature reference for known exploit traffic.
  • Review SYS600 logs for critical function invocations that occur without a preceding authentication event.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-5620 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-3980Hitachienergy microscada pro sys600 path traversal vulnerabilityThe MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operat…EPSS 0.61%8.8CVE-2024-4872Hitachienergy microscada pro sys600 vulnerabilityA vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inj…EPSS 0.50%7.8CVE-2022-3388Hitachienergy microscada pro sys600 improper input validation vulnerabilityAn input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an …EPSS 0.29%8.8CVE-2026-67277MikroTik RouterOS btest missing authentication leaks kernel memory and crashes kernelRouterOS accepts a "related" btest connection before the primary session is authenticated, letting an unauthenticated client start an IPv4 UDP test. …KEVEPSS 1.6%analysed8.8CVE-2026-59822LiteLLM MCP endpoint auth bypass via OAuth2 passthrough fallbackLiteLLM's MCP Streamable HTTP endpoint, prior to 1.84.0, let an unauthenticated attacker send a fabricated Authorization header that triggered an OAu…KEVEPSS 0.84%analysed9.3CVE-2026-72529TrueConf Server missing authentication allows remote script executionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier expose an undocumented function on port 4307/TCP …KEVEPSS 1.5%analysed9.8CVE-2026-46817Oracle E-Business Suite Payments missing authentication allows takeoverOracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthen…KEVEPSS 0.81%analysed9.8CVE-2026-56164Microsoft SharePoint Server missing authentication allows privilege elevationMicrosoft Office SharePoint Server contains a missing authentication flaw in a critical function (CWE-306), letting an unauthenticated attacker reach…KEVEPSS 1.0%analysed

Source: NIST National Vulnerability Database (record CVE-2019-5620), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.