← Vulnerability feed

Vulnerability record · CVE-2022-3388 · published 21 November 2022

CVE-2022-3388: Hitachienergy microscada pro sys600 improper input validation vulnerability

Hitachienergy · Microscada Pro Sys600

An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

7.8 CVSS 3.1 High EPSS 0.29% · top 80.4% CWE-20 · Improper input validation
7.8CVSS 3.1 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-3388 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-7940Hitachienergy microscada x sys600 missing authentication for critical function vulnerabilityThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.58%9.8CVE-2019-5620ABB MicroSCADA Pro SYS600 Missing Authentication for Critical FunctionABB MicroSCADA Pro SYS600 version 9.3 contains a missing authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can…EPSS 70%analysed8.8CVE-2024-3980Hitachienergy microscada pro sys600 path traversal vulnerabilityThe MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operat…EPSS 0.61%8.8CVE-2024-4872Hitachienergy microscada pro sys600 vulnerabilityA vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inj…EPSS 0.50%8.8CVE-2022-29490Hitachienergy microscada x sys600 improper authorization vulnerabilityImproper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execut…EPSS 0.62%8.5CVE-2026-9854Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator le…EPSS 0.14%8.5CVE-2026-9853Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify…EPSS 0.14%8.5CVE-2025-39204Hitachienergy microscada x sys600 information exposure vulnerabilityA vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returni…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2022-3388), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.