First published: Wed Sep 14 2022(Updated: )
Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration file causes a buffer-overflow that causes a failure to start the SYS600. The configuration file can only be accessed by an administrator access. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1. cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*
Credit: cybersecurity@hitachienergy.com cybersecurity@hitachienergy.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hitachienergy Microscada X Sys600 | >=10.0<=10.3.1 | |
Hitachienergy Sys600 | ||
All of | ||
Hitachienergy Microscada X Sys600 | >=10.0<=10.3.1 | |
Hitachienergy Sys600 |
Remediated in SYS600 10.4 Update to at least SYS600 version 10.4.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-1778.
The severity level of CVE-2022-1778 is high.
The Hitachi Energy MicroSCADA X SYS600 software is affected by CVE-2022-1778.
CVE-2022-1778 causes a buffer overflow in the SYS600, which leads to a failure to start the system.
Yes, administrator access is required to access the specific configuration file that triggers the vulnerability.