A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself.
Only the SYS600 system users should be permitted to view and modify application objects.
References
| Link | Resource |
|---|---|
| https://publisher.hitachienergy.com/preview?DocumentID=8DBD000249&LanguageCode=en&DocumentPartId=&Action=Launch | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-09-03 13:06
Updated : 2026-09-09 19:36
NVD link : CVE-2026-9853
Mitre link : CVE-2026-9853
CVE.ORG link : CVE-2026-9853
JSON object : View
Products Affected
hitachienergy
- microscada_x_sys600
CWE
CWE-303
Incorrect Implementation of Authentication Algorithm
