CVE-2022-3388: Input Validation Vulnerability in Hitachi Energy’s MicroSCADA Pro/X SYS600 Products

Published Nov 21, 2022
·
Updated

An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

Affected Software

13 affected components
hitachienergy Microscada Pro Sys600=9.0
hitachienergy Microscada Pro Sys600=9.1
hitachienergy Microscada Pro Sys600=9.2
hitachienergy Microscada Pro Sys600=9.3
hitachienergy Microscada Pro Sys600=9.4
hitachienergy MicroSCADA X SYS600=10
hitachienergy MicroSCADA X SYS600=10.1
hitachienergy MicroSCADA X SYS600=10.1.1
hitachienergy MicroSCADA X SYS600=10.2
hitachienergy MicroSCADA X SYS600=10.2.1
hitachienergy MicroSCADA X SYS600=10.3
hitachienergy MicroSCADA X SYS600=10.3.1
hitachienergy MicroSCADA X SYS600=10.4

Remediation

Information

For SYS600 9.x: update to at SYS600 version SYS600 9.4 FP2 Hotfix 5 when it is released or upgrade to at least SYS600 version 10.4.1. A requirement to install SYS600 9.4 FP2 Hotfix 5 is to have at least the SYS600 9.4 FP2 Hotfix 4 installed. CPE:  cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.0:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:*:*:*:*:*:*:*

Information

For SYS600 10.x update to at least SYS600 version 10.4.1 Or apply general mitigation factors. CPE:  cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:* cpe:2.3:a:hitachienergy:microscada_x_sys600:10.4:*:*:*:*:*:*:*

Event History

Nov 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-3388?

CVE-2022-3388 is an input validation vulnerability in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600.

2

How severe is CVE-2022-3388?

CVE-2022-3388 has a severity rating of 7.8 (high).

3

Which software versions are affected by CVE-2022-3388?

MicroSCADA Pro versions 9.0 to 9.4 and MicroSCADA X SYS600 versions 10 to 10.4 are affected by CVE-2022-3388.

4

How can an authenticated user exploit CVE-2022-3388?

An authenticated user can launch an administrator level remote code execution regardless of their role.

5

Where can I find more information about CVE-2022-3388?

You can find more information about CVE-2022-3388 at the following link: [https://search.abb.com/library/Download.aspx?DocumentID=8DBD000123&LanguageCode=en&DocumentPartId=&Action=Launch&elqaid=4293&elqat=1](https://search.abb.com/library/Download.aspx?DocumentID=8DBD000123&LanguageCode=en&DocumentPartId=&Action=Launch&elqaid=4293&elqat=1)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203