← Vulnerability feed

Vulnerability record · CVE-2022-29490 · published 12 September 2022

CVE-2022-29490: Hitachienergy microscada x sys600 improper authorization vulnerability

Hitachienergy · Microscada X Sys600

Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*

8.8 CVSS 3.1 High EPSS 0.62% · top 52.3% CWE-285 · Improper authorization
8.8CVSS 3.1 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-29490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-7940Hitachienergy microscada x sys600 missing authentication for critical function vulnerabilityThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.58%8.8CVE-2024-3980Hitachienergy microscada pro sys600 path traversal vulnerabilityThe MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operat…EPSS 0.61%8.8CVE-2024-4872Hitachienergy microscada pro sys600 vulnerabilityA vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inj…EPSS 0.50%8.5CVE-2026-9854Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator le…EPSS 0.14%8.5CVE-2026-9853Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify…EPSS 0.14%8.5CVE-2025-39204Hitachienergy microscada x sys600 information exposure vulnerabilityA vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returni…EPSS 0.36%8.3CVE-2025-39202Hitachienergy microscada x sys600 improper privilege management vulnerabilityA vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and over…EPSS 0.23%8.2CVE-2024-3982Hitachienergy microscada x sys600 authentication bypass by capture-replay vulnerabilityAn attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to e…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2022-29490), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.