CVE-2024-4872: Hitachienergy Microscada Pro SYS600
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
Affected products
- Hitachienergy Microscada Pro SYS600: version 9.4 only
- Hitachienergy Microscada X SYS600: from 10.0, before 10.6 (fixed in 10.6)
Published 2024-08-27. Last modified 2026-06-17.