A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.
History

Wed, 09 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy microscada X Sys600
CPEs cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:*
Vendors & Products Hitachienergy microscada X Sys600
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 03 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Title OS‑Level Access Allows Unauthorized Modification of SYS600 Objects

Thu, 03 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Hitachienergy
Hitachienergy microscada Sys600
Vendors & Products Hitachienergy
Hitachienergy microscada Sys600

Thu, 03 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects.
Weaknesses CWE-303
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi Energy

Published: 2026-09-03T07:53:35.276Z

Updated: 2026-09-03T12:49:23.783Z

Reserved: 2026-05-28T15:04:56.583Z

Link: CVE-2026-9853

cve-icon Vulnrichment

Updated: 2026-09-03T12:49:20.468Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-03T13:06:25.943

Modified: 2026-09-09T19:36:31.563

Link: CVE-2026-9853

cve-icon Redhat

No data.