CVE-2025-39205

Severity CVSS v4.0:
HIGH
Type:
CWE-295 Improper Certificate Validation
Publication date:
24/06/2025
Last modified:
30/01/2026

Description

A vulnerability exists in the IEC 61850 in MicroSCADA X SYS600 product. The certificate validation of the TLS protocol allows remote Man-in-the-Middle attack due to missing proper validation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:* 10.3 (including) 10.7 (excluding)