CVE-2022-29490: A vulnerability exists in the Workplace X WebUI in which an authenticated user is able to execute any MicroSCADA internal scripts irrespective of the authenticated user's role.
Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1. cpe:2.3:a:hitachienergy:microscadaxsys600:10::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.1.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.2.1::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3::::::: cpe:2.3:a:hitachienergy:microscadaxsys600:10.3.1:::::::
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-29490.
What is the severity of CVE-2022-29490?
The severity of CVE-2022-29490 is high, with a severity value of 8.8.
Which software is affected by CVE-2022-29490?
The Hitachi Energy MicroSCADA X SYS600 version 10 to v10.3.1 is affected by CVE-2022-29490.
How does the vulnerability in the Workplace X WebUI of Hitachi Energy MicroSCADA X SYS600 allow an authenticated user to execute any MicroSCADA internal scripts?
The vulnerability in the Workplace X WebUI of Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role.
Is Hitachi Energy Sys600 vulnerable to this vulnerability?
No, Hitachi Energy Sys600 is not vulnerable to this vulnerability.