CVE-2019-5620

CRITICAL

ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.

Affects 3 products across 2 vendors.

BCS7.86
CVSS 3.19.8
EPSS70.1%
Percentile99th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-306: Missing Authentication for Critical Function

Software does not perform any authentication for functionality that requires a verified identity.

Related Attack Patterns (CAPEC)
CAPEC-12 Choosing Message Identifier
via CWE-306
CAPEC-36 Using Unpublished Interfaces or Functionality
via CWE-306
CAPEC-62 Cross Site Request Forgery
via CWE-306
CAPEC-166 Force the System to Reset Values
via CWE-306
CAPEC-216 Communication Channel Manipulation
via CWE-306

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

ABB MicroSCADA Pro SYS600 version 9.3 is vulnerable to CWE-306: Missing Authentication for Critical Function, which could allow unauthorized access to critical system functions.

BSID: BS-2020-GLOBAL-140426-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2019-5620?
ABB MicroSCADA Pro SYS600 version 9.3 is vulnerable to CWE-306: Missing Authentication for Critical Function, which could allow unauthorized access to critical system functions.
What is the CVSS score for CVE-2019-5620?
CVE-2019-5620 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 70.1%.
Is CVE-2019-5620 actively exploited?
No confirmed active exploitation of CVE-2019-5620 as of 2026-09-25.
How do I remediate CVE-2019-5620?
Priority: IMMEDIATE.
What systems are affected by CVE-2019-5620?
CVE-2019-5620 affects: Hitachienergy, Microsoft, Microsoft.
Vulnerability Details
CVE IDCVE-2019-5620
BSIDBS-2020-GLOBAL-140426-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2020-04-29
Last Modified2026-06-17
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker could exploit this vulnerability by sending specially crafted requests to the affected system, potentially gaining unauthorized access to critical functions without proper authentication.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Hitachienergy Microscada Pro Sys600 —
Microsoft Windows Xp —
Microsoft Windows 7 —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 2342 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashf4ad4a21e9d034fef1d9e2748a4b4c333291271a8c01e50c0ff694bceb8a4061103bb0d3a66d0d7c9dcdc536bd1f645fa83d16de207d695d23b26d3260e98325
Related CVEs affecting Hitachienergy
CVE-2024-2013 10.0 An authentication bypass vulnerability exists in the FOXMAN-UN/UNEM server / ... CVE-2019-18253 10.0 An attacker could use specially crafted paths in a specific request to read o... CVE-2022-3927 9.8 The affected products store both public and private key that are used to sig... CVE-2018-14805 9.8 ABB eSOMS version 6.0.2 may allow unauthorized access to the system when LDAP... CVE-2021-40342 9.8 In the DES implementation, the affected product versions use a default key f...
View all Hitachienergy CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →