Microscada sys600
This hub aggregates every CVE we track for Microscada sys600, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
6
CVEs tracked
0
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5MEDIUM1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
3
2024-102026-09
Latest CVEs
The 6 most recently published vulnerabilities affecting Microscada sys600.
- CVE-2026-9854A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting the...7.8
- CVE-2026-9853A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated...7.8
- CVE-2026-9852A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user ha...7.8
- CVE-2024-7941An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfu...4.3
- CVE-2024-7940The product exposes a service that is intended for local only to all network interfaces without any authentication.8.3
- CVE-2024-3982An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already establi...8.2
Product normalization is registry-driven with AI assist and human review. How it works