You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
pcm600 vulnerability
About this tag
The pcm600 vulnerability tag covers a path-traversal flaw in Hitachi Energy's PCM600 engineering software, used to configure protection-and-control equipment in the energy sector. CISA republished an advisory on May 5, 2026, warning that affected legacy and 3.x versions mishandle malicious ZIP archives, allowing attackers to write files outside the intended extraction path. While the CVSS score is medium, the issue is notable because a 2018 software-supply-chain bug has resurfaced in industrial tooling. For operators, this highlights that engineering workstations are part of the attack surface. Discussions on WindowsForum.com focus on the implications for OT environments and the need for patching legacy systems.
CISA on May 5, 2026 republished Hitachi Energy’s advisory for a path-traversal flaw in PCM600, warning that affected legacy and 3.x versions can mishandle malicious ZIP archives and allow an attacker to write files outside the intended extraction path. The uncomfortable part is not the CVSS...