Vulnerabilities > Hitachienergy

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2022-3927 Use of Hard-coded Credentials vulnerability in Hitachienergy Foxman-Un and Unem
The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification.
network
low complexity
hitachienergy CWE-798
critical
9.8
2023-01-05 CVE-2022-3928 Use of Hard-coded Credentials vulnerability in Hitachienergy Foxman-Un and Unem
Hardcoded credential is found in affected products' message queue.
local
low complexity
hitachienergy CWE-798
5.5
2023-01-05 CVE-2022-3929 Cleartext Transmission of Sensitive Information vulnerability in Hitachienergy Foxman-Un and Unem
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP.
network
low complexity
hitachienergy CWE-319
critical
9.8
2022-11-22 CVE-2022-2513 Cleartext Storage of Sensitive Information vulnerability in Hitachienergy products
A vulnerability exists in the Intelligent Electronic Device (IED) Connectivity Package (ConnPack) credential storage function in Hitachi Energy’s PCM600 product included in the versions listed below, where IEDs credentials are stored in a cleartext format in the PCM600 database and logs files.
local
low complexity
hitachienergy CWE-312
5.5
2022-11-21 CVE-2022-3388 Improper Input Validation vulnerability in Hitachienergy Microscada PRO Sys600 and Microscada X Sys600
An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600.
local
low complexity
hitachienergy CWE-20
7.8
2022-09-14 CVE-2022-1778 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Hitachienergy Microscada X Sys600
Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a specific configuration file causes a buffer-overflow that causes a failure to start the SYS600.
local
low complexity
hitachienergy CWE-119
4.4
2022-09-14 CVE-2022-29492 Improper Input Validation vulnerability in Hitachienergy Microscada X Sys600
Improper Input Validation vulnerability in the handling of a malformed IEC 104 TCP packet in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro SYS600.
network
low complexity
hitachienergy CWE-20
7.5
2022-09-14 CVE-2022-29922 Improper Input Validation vulnerability in Hitachienergy Microscada X Sys600
Improper Input Validation vulnerability in the handling of a specially crafted IEC 61850 packet with a valid data item but with incorrect data type in the IEC 61850 OPC Server in the Hitachi Energy MicroSCADA X SYS600, MicroSCADA Pro SYS600.
network
low complexity
hitachienergy CWE-20
7.5
2022-09-14 CVE-2022-2277 Improper Validation of Specified Quantity in Input vulnerability in Hitachienergy Microscada X Sys600
Improper Input Validation vulnerability exists in the Hitachi Energy MicroSCADA X SYS600's ICCP stack during the ICCP communication establishment causes a denial-of-service when ICCP of SYS600 is request to forward any data item updates with timestamps too distant in the future to any remote ICCP system.
network
low complexity
hitachienergy CWE-1284
7.5
2022-09-12 CVE-2022-29490 Unspecified vulnerability in Hitachienergy Microscada X Sys600
Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role.
network
low complexity
hitachienergy
8.8