Executive brief
SYS600 is a power system management application used by utilities to control and monitor electrical infrastructure. A vulnerability allows any user with operating system access to the server to view and modify critical application data without needing legitimate SYS600 credentials, potentially enabling unauthorized changes to power system configurations or data theft.
Technical details
The vulnerability is an authentication bypass flaw in SYS600 that permits OS-level access to the server to escalate into application-level access. An attacker with local system access (such as through compromised credentials or direct server access) can read and modify application objects that should only be accessible to authenticated SYS600 users. The attack requires local/physical access to the server or prior compromise of OS-level credentials. No authentication to the SYS600 system itself is required once OS-level access is obtained. A patch is available as indicated by the published advisory.
Affected products
- Hitachi Energy SYS600
Timeline
- 2026-09-03: disclosed