ZeroHour

CVE-2026-9853

moderate

Authentication Bypass in Hitachi Energy MicroSCADA X SYS600

CVSS 4.0
8.5 high
EPSS
<1%p3
Published
()
Modified
AI analysis

MicroSCADA X SYS600, Hitachi Energy's SCADA/energy-management platform, fails to enforce its own application-level authentication: any user holding a valid account on the hosting server's operating system can read and modify SYS600 application objects without authenticating to SYS600 itself (CWE-303). The CVSS 4.0 vector (AV:L/PR:L/UI:N) indicates exploitation requires only low-privilege local access to the hosting server and no user interaction. An attacker — typically an insider, a compromised local account, or another process on the host — can therefore view and alter application objects, with high confidentiality, integrity, and availability impacts producing a score of 8.5 (High). Customers running MicroSCADA X SYS600 are affected, especially control-room servers where non-SYS600 personnel have OS logon rights; no affected or fixed version ranges were specified in the source data. No public proof-of-concept, KEV listing, or elevated EPSS (0.1%) is known, so exploitation has not been observed.

What to do: As an interim control, restrict operating-system logon rights on SYS600 host servers to authorized SYS600 users and service accounts, and audit existing local accounts on those servers. Consult the Hitachi Energy security advisory for CVE-2026-9853 to identify patched MicroSCADA X SYS600 releases and upgrade when available, since no fixed versions are listed in the source data.

Affected
Hitachi Energy MicroSCADA X SYS600
Estimated exposure
moderateOrder of thousands of utility control-center/substation installations (no published install count in source data) — No install counts appear in the source data; the estimate reflects the deployment pattern of this specialized utility SCADA platform, which is installed per control center and substation across the energy sector rather than as mass-market…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.

Vendors
hitachienergy
Products
microscada x sys600
Weakness
CWE-303
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.