CVE-2025-39205: Hitachienergy Microscada X SYS600

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

Affected products

  • Hitachienergy Microscada X SYS600: from 10.3, before 10.7 (fixed in 10.7)

Published 2025-06-24. Last modified 2026-06-17.