CVE-2025-39203: Hitachienergy Microscada X SYS600

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop.

Affected products

  • Hitachienergy Microscada X SYS600: from 10.5, before 10.7 (fixed in 10.7)

Published 2025-06-24. Last modified 2026-06-17.