Hitachienergy develops industrial automation, power systems, and energy-management software and appliances that sit at the intersection of operational technology and IT infrastructure, presenting a critical attack surface in electricity grids, manufacturing facilities, and utility networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the high-consequence nature of power-system and control-system compromise. The exposure concentrates across products including ESOMS, MicroSCADA X SYS600, FOXMAN UN, UNEM, and REL670 and recurs through weakness classes centered on improper input validation and cross-site scripting, coupled with instances of sensitive information disclosure—typical of legacy industrial-control software where authentication and boundary validation are often secondary to functionality. Defenders should prioritize patching for these products, especially those deployed in internet-connected or DMZ-adjacent roles, and treat exposures in power infrastructure as high-consequence; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hitachienergy over time
Signals from CVEs in this vendor scope (104 CVEs).
104 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5620CRITICAL ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function. | Apr 29, 2020 | 9.8 | 78 | NO | YES |
CVE-2024-2013CRITICAL An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server /
API Gateway component that if exploited allows attackers without
any access to interact with the servi | Jun 11, 2024 | 10.0 | 33 | NO | NO |
CVE-2024-2012CRITICAL vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or
code to be executed on the UNEM server allo | Jun 11, 2024 | 9.8 | 33 | NO | NO |
CVE-2018-14805CRITICAL ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are | Aug 29, 2018 | 9.8 | 32 | NO | NO |
CVE-2024-2011CRITICAL A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that
if exploited will generally lead to a denial of service but can be used
to execute arbitrary code, whi | Jun 11, 2024 | 9.8 | 31 | NO | NO |
CVE-2022-3927CRITICAL
The affected products store both public and private key that are used to sign and
protect Custom Parameter Set (CPS) file from modification. An attacker that manages to exploit th | Jan 5, 2023 | 9.8 | 31 | NO | NO |
CVE-2019-18253CRITICAL An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, an | Nov 27, 2019 | 10.0 | 31 | NO | NO |
CVE-2024-4872HIGH A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent dat | Aug 27, 2024 | 8.8 | 30 | NO | NO |
CVE-2022-3686CRITICAL A vulnerability exists in a SDM600 endpoint.
An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the a | Mar 28, 2023 | 9.1 | 30 | NO | NO |
CVE-2022-3929CRITICAL
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This pr | Jan 5, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (104 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hitachienergy.
Media articles that mention a CVE ID that affects a product developed by Hitachienergy — matched by CVE ID, not by vendor name.