CVE-2025-39201: Medium severity Siemens MicroSCADA X SYS600 vulnerability
Published Jun 24, 2025
·Updated
A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.
Affected Software
2 affected components
Siemens MicroSCADA X SYS600
hitachienergy MicroSCADA X SYS600>=10.0<10.7
Event History
Jun 24, 2025
CVE Published
via MITRE·11:46 AM
Data Sourced
via MITRE·11:46 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39201?
CVE-2025-39201 is considered a critical security vulnerability due to its potential to allow local unauthenticated attackers to tamper with system files.
2
How do I fix CVE-2025-39201?
To fix CVE-2025-39201, ensure that all available updates and patches for MicroSCADA X SYS600 are applied immediately.
3
Who is affected by CVE-2025-39201?
CVE-2025-39201 affects users of the Siemens MicroSCADA X SYS600 product.
4
What are the potential impacts of CVE-2025-39201?
Exploitation of CVE-2025-39201 could lead to a denial of Notify service, disrupting normal operations.
5
Is CVE-2025-39201 remotely exploitable?
CVE-2025-39201 is not remotely exploitable, as it requires local access to the affected system.