CVE Tools

Hitachi-energy

63 CVEs tracked since 2021. Since Nov 2021, none of them reached CISA KEV.

Hitachi-energy CVEs per month

Nov 2021 to Jun 2025. Point at a month, or focus the strip and use the arrow keys.
Hitachi-energy CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-1140
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-0630
2022-07null or fewer
2022-08null or fewer
2022-0950
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-0160
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-1150
2023-1260
2024-01null or fewer
2024-02null or fewer
2024-0350
2024-04null or fewer
2024-05null or fewer
2024-06100
2024-07null or fewer
2024-0850
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-0370
2025-04null or fewer
2025-05null or fewer
2025-0670

Products

The products that kept showing up in Hitachi-energy's monthly top three, with their CVEs summed over those months.

  1. Foxman-un142 months
  2. Unem142 months
  3. Microscada X SYS600123 months
  4. RTU50062 months
  5. Microscada Pro SYS60042 months
  6. Esoms31 month
  7. Microscada SYS60031 month
  8. Trmtracker31 month
  9. Txpert Hub Coretec 4 Version31 month
  10. FOX61X21 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Hitachi-energy.

  1. CVE-2026-17539RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL pointer dereference in the last entry of the enhanced message queue. This can...5.9
  2. CVE-2026-9854A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting the...7.8
  3. CVE-2026-9853A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated...7.8
  4. CVE-2026-9852A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user ha...7.8
  5. CVE-2026-10763PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.7.1
  6. CVE-2026-8479IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for a certain time, causing Denial of Servic...6.5
  7. CVE-2026-7310A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using a specially craft...5.5
  8. CVE-2026-2460A vulnerability exists in REB500 for an authenticated user with low-level privileges to access and alter the content of directories by using the DAC protocol that the user is not authorized to do so.8.1
  9. CVE-2026-2459A vulnerability exists in REB500 for an authenticated user with Installer role to access and alter the contents of directories that the role is not authorized to do so.8.1
  10. CVE-2026-1773IEC 60870-5-104 used in RTU500: Potential Denial of Service impact on reception of invalid U-format frame. Product is only affected if IEC 60870-5-104 bi-directional functionality is configured. E...7.5
  11. CVE-2026-1772RTU500 web interface: An unprivileged user can read user management information. The information cannot be accessed via the RTU500 web user interface but requires further tools like browser develop...5.3
  12. CVE-2025-7740Use of default credentials vulnerability in Hitachi Energy SuprOS product8.8
  13. CVE-2025-1038The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticated user with high privileges to inject commands into...8.8
  14. CVE-2025-1037By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user level shell commands can enable access via secure shell (SSH) to an unrestrict...8.8
  15. CVE-2025-1036Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privileged network access for the configuration utility can e...8.8

The record

Peak rank
#70 in Jun 2024
Busiest month shown
Jun 2024, 10 CVEs
Months with a KEV entry
0 since Nov 2021
Monthly snapshots
11 since 2021
Hitachi-energy's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store