CVE-2023-28384
- EPSS 68.37%
- Veröffentlicht 27.04.2023 23:15:14
- Zuletzt bearbeitet 17.01.2025 17:15:07
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
CVE-2022-2234
- EPSS 0.45%
- Veröffentlicht 24.08.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:00:35
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
CVE-2021-33009
- EPSS 0.22%
- Veröffentlicht 13.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:07
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.
CVE-2021-33013
- EPSS 0.22%
- Veröffentlicht 13.05.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:07
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
CVE-2021-33005
- EPSS 0.34%
- Veröffentlicht 13.05.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:08:06
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.
CVE-2021-27505
- EPSS 0.21%
- Veröffentlicht 13.05.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:07
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information.
- EPSS 0.37%
- Veröffentlicht 11.04.2022 20:15:16
- Zuletzt bearbeitet 21.11.2024 06:39:49
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
- EPSS 0.3%
- Veröffentlicht 23.12.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:31:00
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
CVE-2021-43989
- EPSS 0.1%
- Veröffentlicht 23.12.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:30:09
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
CVE-2021-43987
- EPSS 0.23%
- Veröffentlicht 23.12.2021 20:15:11
- Zuletzt bearbeitet 21.11.2024 06:30:09
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.