Vulnerability record · CVE-2019-5620 · published 29 April 2020
CVE-2019-5620: ABB MicroSCADA Pro SYS600 Missing Authentication for Critical Function
Hitachienergy · Microscada Pro Sys600
ABB MicroSCADA Pro SYS600 version 9.3 contains a missing authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can reach that function over the network, which matters because the product is used in SCADA/industrial control environments.
Description
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network-reachable, unauthenticated access to a critical function in a SCADA product, plus very high EPSS, makes this a top remediation priority.
What it is
ABB MicroSCADA Pro SYS600 version 9.3 contains a missing authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can reach that function over the network, which matters because the product is used in SCADA/industrial control environments.
Impact
An attacker gains full compromise of confidentiality, integrity and availability of the affected system, with CVSS 3.1 scoring 9.8. In a SCADA context this can translate into control over the process or host.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the flaw is reachable over the network with no authentication and no user interaction. The description does not identify the specific endpoint or service, only that a critical function lacks authentication.
Exploitation
Not listed in CISA KEV, but EPSS is 0.70081 (99.3rd percentile), indicating a high modeled likelihood of exploitation. A Rapid7 Metasploit module reference (abb_wserver_exec) exists, though the record does not state whether it has been used in the wild.
What to do
- Apply the vendor fix for ABB MicroSCADA Pro SYS600 9.3; if no patch is available, isolate affected systems.
- Restrict network access to SYS600 hosts with firewall rules and segmentation so only trusted management networks can reach them.
- Place SYS600 behind a hardened jump host or VPN requiring authentication for any administrative or service access.
- Monitor vendor advisories for updated fixed versions and upgrade as soon as they are released.
- Disable or block any unnecessary services and ports on SYS600 hosts that are not required for operations.
Detection
- Monitor network traffic to SYS600 hosts for unexpected connections to service ports from untrusted sources.
- Alert on authentication-free access attempts or anomalous process execution on SYS600 systems.
- Use the Rapid7 Metasploit module name abb_wserver_exec as a signature reference for known exploit traffic.
- Review SYS600 logs for critical function invocations that occur without a preceding authentication event.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.rapid7.com/db/modules/exploit/windows/scada/abb_wserver_exec | Third Party Advisory |
| https://www.rapid7.com/db/modules/exploit/windows/scada/abb_wserver_exec | Third Party Advisory |
Track CVE-2019-5620 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-5620), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.