CVE-2022-3388: Input Validation Vulnerability in Hitachi Energy’s MicroSCADA Pro/X SYS600 Products
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2022-3388?
CVE-2022-3388 is an input validation vulnerability in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600.
How severe is CVE-2022-3388?
CVE-2022-3388 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2022-3388?
MicroSCADA Pro versions 9.0 to 9.4 and MicroSCADA X SYS600 versions 10 to 10.4 are affected by CVE-2022-3388.
How can an authenticated user exploit CVE-2022-3388?
An authenticated user can launch an administrator level remote code execution regardless of their role.
Where can I find more information about CVE-2022-3388?
You can find more information about CVE-2022-3388 at the following link: [https://search.abb.com/library/Download.aspx?DocumentID=8DBD000123&LanguageCode=en&DocumentPartId=&Action=Launch&elqaid=4293&elqat=1](https://search.abb.com/library/Download.aspx?DocumentID=8DBD000123&LanguageCode=en&DocumentPartId=&Action=Launch&elqaid=4293&elqat=1)