← Vulnerability feed

Vulnerability record · CVE-2025-39204 · published 24 June 2025

CVE-2025-39204: Hitachienergy microscada x sys600 information exposure vulnerability

Hitachienergy · Microscada X Sys600

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.

8.5 CVSS 4.0 High EPSS 0.36% · top 72.6% CWE-200 · Information exposure
8.5CVSS 4.0 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-39204 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-7940Hitachienergy microscada x sys600 missing authentication for critical function vulnerabilityThe product exposes a service that is intended for local only to all network interfaces without any authentication.EPSS 0.58%8.8CVE-2024-3980Hitachienergy microscada pro sys600 path traversal vulnerabilityThe MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operat…EPSS 0.61%8.8CVE-2024-4872Hitachienergy microscada pro sys600 vulnerabilityA vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inj…EPSS 0.50%8.8CVE-2022-29490Hitachienergy microscada x sys600 improper authorization vulnerabilityImproper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execut…EPSS 0.62%8.5CVE-2026-9854Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator le…EPSS 0.14%8.5CVE-2026-9853Hitachienergy microscada x sys600 vulnerabilityA vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify…EPSS 0.14%8.3CVE-2025-39202Hitachienergy microscada x sys600 improper privilege management vulnerabilityA vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and over…EPSS 0.23%8.2CVE-2024-3982Hitachienergy microscada x sys600 authentication bypass by capture-replay vulnerabilityAn attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to e…EPSS 0.22%

Source: NIST National Vulnerability Database (record CVE-2025-39204), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.