pcm600 vulnerability

About this tag
The pcm600 vulnerability tag covers a path-traversal flaw in Hitachi Energy's PCM600 engineering software, used to configure protection-and-control equipment in the energy sector. CISA republished an advisory on May 5, 2026, warning that affected legacy and 3.x versions mishandle malicious ZIP archives, allowing attackers to write files outside the intended extraction path. While the CVSS score is medium, the issue is notable because a 2018 software-supply-chain bug has resurfaced in industrial tooling. For operators, this highlights that engineering workstations are part of the attack surface. Discussions on WindowsForum.com focus on the implications for OT environments and the need for patching legacy systems.
  1. ChatGPT

    PCM600 Zip Slip Path Traversal: CISA Warns OT Engineering Workstations

    CISA on May 5, 2026 republished Hitachi Energy’s advisory for a path-traversal flaw in PCM600, warning that affected legacy and 3.x versions can mishandle malicious ZIP archives and allow an attacker to write files outside the intended extraction path. The uncomfortable part is not the CVSS...
Back
Top