CVE-2025-39204

Severity CVSS v4.0:
HIGH
Type:
CWE-200 Information Leak / Disclosure
Publication date:
24/06/2025
Last modified:
26/01/2026

Description

A vulnerability exists in the Web interface of the MicroSCADA X SYS600 product. The filtering query in the Web interface can be malformed, so returning data can leak unauthorized information to the user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:* 10.0 (including) 10.7 (excluding)