Vulnerabilities
Vulnerable Software
Myscada:  >> Mypro  >> 7.0.26  Security Vulnerabilities
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-05-13
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
CVSS Score
8.8
EPSS Score
0.003
Published
2022-04-11
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
CVSS Score
10.0
EPSS Score
0.003
Published
2021-12-23
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
CVSS Score
10.0
EPSS Score
0.003
Published
2021-12-23
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
CVSS Score
9.1
EPSS Score
0.002
Published
2021-12-23
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
CVSS Score
9.8
EPSS Score
0.002
Published
2021-12-23
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-12-23
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
CVSS Score
10.0
EPSS Score
0.003
Published
2021-12-23
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
CVSS Score
10.0
EPSS Score
0.004
Published
2021-12-23
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
CVSS Score
10.0
EPSS Score
0.004
Published
2021-12-23


Contact Us

Shodan ® - All rights reserved