CVE-2022-3388

An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.0:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.2:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.3:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.4:*:*:*:*:*:*:*

History

19 Oct 2023, 05:15

Type Values Removed Values Added
Summary An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role. An input validation vulnerability exists in the Monitor Pro interface of MicroSCADA Pro and MicroSCADA X SYS600. An authenticated user can launch an administrator level remote code execution irrespective of the authenticated user's role.

08 Dec 2022, 15:26

Type Values Removed Values Added
First Time Hitachienergy microscada Pro Sys600
Hitachienergy microscada X Sys600
Hitachienergy
CPE cpe:2.3:a:abb:microscada_pro_sys600:9.4:fixpack_1:*:*:*:*:*:*
cpe:2.3:a:abb:microscada_pro_sys600:9.4:-:*:*:*:*:*:*
cpe:2.3:a:abb:microscada_pro_sys600:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:microscada_pro_sys600:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:microscada_pro_sys600:-:*:*:*:*:*:*:*
cpe:2.3:a:abb:microscada_pro_sys600:9.4:fixpack_2:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.0:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.2:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.3:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.4:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.2:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.4:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_pro_sys600:9.3:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10.1:*:*:*:*:*:*:*
cpe:2.3:a:hitachienergy:microscada_x_sys600:10:*:*:*:*:*:*:*

28 Nov 2022, 15:27

Type Values Removed Values Added
CWE CWE-20
References (MISC) https://search.abb.com/library/Download.aspx?DocumentID=8DBD000123&LanguageCode=en&DocumentPartId=&Action=Launch&elqaid=4293&elqat=1 - (MISC) https://search.abb.com/library/Download.aspx?DocumentID=8DBD000123&LanguageCode=en&DocumentPartId=&Action=Launch&elqaid=4293&elqat=1 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:abb:microscada_pro_sys600:9.4:fixpack_1:*:*:*:*:*:*
cpe:2.3:a:abb:microscada_pro_sys600:9.4:-:*:*:*:*:*:*
cpe:2.3:a:abb:microscada_pro_sys600:*:*:*:*:*:*:*:*
cpe:2.3:o:abb:microscada_pro_sys600:*:*:*:*:*:*:*:*
cpe:2.3:h:abb:microscada_pro_sys600:-:*:*:*:*:*:*:*
cpe:2.3:a:abb:microscada_pro_sys600:9.4:fixpack_2:*:*:*:*:*:*
First Time Abb
Abb microscada Pro Sys600

21 Nov 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-21 19:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-3388

Mitre link : CVE-2022-3388

CVE.ORG link : CVE-2022-3388


JSON object : View

Products Affected

hitachienergy

  • microscada_x_sys600
  • microscada_pro_sys600
CWE
CWE-20

Improper Input Validation