CVE-2025-39204

MEDIUM

MicroSCADA X SYS600 10.0-10.7 - Exposure of Sensitive Information via Web Interface Query Filtering

Title source: llm
STIX 2.1

Description

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.

Scores

CVSS v3 6.5
EPSS 0.0031
EPSS Percentile 22.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
hitachienergy/microscada_x_sys600 10.0 - 10.7
Published Jun 24, 2025
Tracked Since Feb 18, 2026