← Vulnerability feed

Vulnerability record · CVE-2024-3980 · published 27 August 2024

CVE-2024-3980: Hitachienergy microscada pro sys600 path traversal vulnerability

Hitachienergy · Microscada Pro Sys600

The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.

8.8 CVSS 3.1 High EPSS 0.61% · top 52.9% CWE-22 · Path traversal
8.8CVSS 3.1 base score
0.61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-3980 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-7940Hitachienergy microscada x sys600 missing authentication for critical function vulnerabilityThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.58%9.8CVE-2019-5620ABB MicroSCADA Pro SYS600 Missing Authentication for Critical FunctionABB MicroSCADA Pro SYS600 version 9.3 contains a missing authentication flaw (CWE-306) in a critical function. An unauthenticated remote attacker can…EPSS 70%analysed8.8CVE-2024-4872Hitachienergy microscada pro sys600 vulnerabilityA vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inj…EPSS 0.50%8.8CVE-2022-29490Hitachienergy microscada x sys600 improper authorization vulnerabilityImproper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execut…EPSS 0.62%8.5CVE-2026-9854Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator le…EPSS 0.14%8.5CVE-2026-9853Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify…EPSS 0.14%8.5CVE-2025-39204Hitachienergy microscada x sys600 information exposure vulnerabilityA vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returni…EPSS 0.36%8.3CVE-2025-39202Hitachienergy microscada x sys600 improper privilege management vulnerabilityA vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and over…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2024-3980), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.