PatchSiren cyber security CVE debrief
CVE-2025-39202 Hitachi Energy CVE debrief
CVE-2025-39202 is a high-severity vulnerability in Hitachi Energy MicroSCADA Pro/X SYS600 affecting the Monitor Pro and Supervision log components. According to CISA’s advisory, a local authenticated low-privilege user can see and overwrite files, which can lead to information leakage and data corruption. Hitachi Energy identifies version 10.7 as the fixed release for affected systems.
- Vendor
- Hitachi Energy
- Product
- MicroSCADA X SYS600
- CVSS
- HIGH 7.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-07-03
- Original CVE updated
- 2025-07-03
- Advisory published
- 2025-07-03
- Advisory updated
- 2025-07-03
Who should care
OT/ICS operators using Hitachi Energy MicroSCADA Pro/X SYS600, especially administrators and defenders responsible for systems running versions 10.0 through 10.5. Site teams should also care if low-privilege local accounts exist on impacted hosts or if file integrity matters for logs and supervision data.
Technical summary
The advisory describes a local attack requiring authentication and low privileges, with no user interaction. The weakness allows the attacker to read and overwrite files in the Monitor Pro and Supervision log area, affecting confidentiality and integrity. CISA’s provided CVSS 3.1 vector is AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H, consistent with a local issue that can still have substantial operational impact. Affected versions are MicroSCADA Pro/X SYS600 >=10.0 and <10.6; version 10.7 is listed as fixed.
Defensive priority
High. If you run an affected MicroSCADA Pro/X SYS600 version, prioritize updating to 10.7 and reducing local access exposure until the upgrade is complete.
Recommended defensive actions
- Upgrade Hitachi Energy MicroSCADA Pro/X SYS600 to version 10.7 as soon as practical.
- Review and restrict local authenticated low-privilege access on affected hosts.
- Check file permissions and integrity controls around Monitor Pro and Supervision log locations.
- Monitor for unexpected file changes or missing integrity in impacted systems and logs.
Evidence notes
The supplied CISA CSAF source item for ICSA-25-184-02 states that the issue affects Hitachi Energy MicroSCADA Pro/X SYS600 versions >=10.0 and <10.6 and that a local authenticated low-privilege user can see and overwrite files, causing information leak and data corruption. The same source lists MicroSCADA X SYS600 10.7 as the fixed version for CVE-2025-39202. The advisory was initially published on 2025-07-03, matching the CVE publication timestamp provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-39202 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-39202
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-39202 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-39202
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-184-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-184-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.