Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hitachienergy

First CVE: Oct 18, 2017Active for: 9 yearsTotal CVEs: 104
37.3
VTI Score
Medium

Hitachienergy develops industrial automation, power systems, and energy-management software and appliances that sit at the intersection of operational technology and IT infrastructure, presenting a critical attack surface in electricity grids, manufacturing facilities, and utility networks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the high-consequence nature of power-system and control-system compromise. The exposure concentrates across products including ESOMS, MicroSCADA X SYS600, FOXMAN UN, UNEM, and REL670 and recurs through weakness classes centered on improper input validation and cross-site scripting, coupled with instances of sensitive information disclosure—typical of legacy industrial-control software where authentication and boundary validation are often secondary to functionality. Defenders should prioritize patching for these products, especially those deployed in internet-connected or DMZ-adjacent roles, and treat exposures in power infrastructure as high-consequence; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
104
Total CVEs
More Total CVEs than 99% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hitachienergy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2017
8 years ago
Most Recent CVE
Feb 24, 2026
151 days ago

Products(68 total)

Top CVEs

Signals from CVEs in this vendor scope (104 CVEs).

104 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-5620CRITICAL
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
Apr 29, 20209.878NOYES
CVE-2024-2013CRITICAL
An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway component that if exploited allows attackers without any access to interact with the servi
Jun 11, 202410.033NONO
CVE-2024-2012CRITICAL
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code to be executed on the UNEM server allo
Jun 11, 20249.833NONO
CVE-2018-14805CRITICAL
ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP is set to allow anonymous authentication, and specific key values within the eSOMS web.config file are
Aug 29, 20189.832NONO
CVE-2024-2011CRITICAL
A heap-based buffer overflow vulnerability exists in the FOXMAN-UN/UNEM that if exploited will generally lead to a denial of service but can be used to execute arbitrary code, whi
Jun 11, 20249.831NONO
CVE-2022-3927CRITICAL
The affected products store both public and private key that are used to sign and protect Custom Parameter Set (CPS) file from modification. An attacker that manages to exploit th
Jan 5, 20239.831NONO
CVE-2019-18253CRITICAL
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, an
Nov 27, 201910.031NONO
CVE-2024-4872HIGH
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent dat
Aug 27, 20248.830NONO
CVE-2022-3686CRITICAL
A vulnerability exists in a SDM600 endpoint. An attacker could exploit this vulnerability by running multiple parallel requests, the SDM600 web services become busy rendering the a
Mar 28, 20239.130NONO
CVE-2022-3929CRITICAL
Communication between the client and the server application of the affected products is partially done using CORBA (Common Object Request Broker Architecture) over TCP/IP. This pr
Jan 5, 20239.830NONO
View all 104 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products104 CVEs
38%
48%
11%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local18 (17.3%)
Network84 (80.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (1.9%)
Attack Complexity
Low98 (94.2%)
High6 (5.8%)
Unknown0 (0.0%)
User Interaction
None87 (83.7%)
Unknown0 (0.0%)
Required17 (16.3%)
Privileges Required
Low35 (33.7%)
High15 (14.4%)
None54 (51.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (104 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hitachienergy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hitachienergy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hitachienergy's Products

View all 6 CNAs →

Top CWEs