CVE-2024-3980 - CVE House
Back to Database
Status published Critical CVE-2024-3980

The MicroSCADA Pro/X SYS600 product allows an authenticated user input...

Vulnerability Description

The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3980

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Hitachi Energy

View all reports →

Affected Software

MicroSCADA X SYS600, MicroSCADA Pro SYS600
Vulnerable Versions:
10.0, 9.4 FP2 HF1, 9.4 FP1

Timeline

Official Publish: August 27th, 2024
Last Modified: August 27th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)