Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In 2021
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
CVSS Score
10.0
EPSS Score
0.003
Published
2021-12-23
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
CVSS Score
10.0
EPSS Score
0.003
Published
2021-12-23
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
CVSS Score
9.1
EPSS Score
0.002
Published
2021-12-23
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
CVSS Score
9.8
EPSS Score
0.002
Published
2021-12-23
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-12-23
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
CVSS Score
10.0
EPSS Score
0.003
Published
2021-12-23
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-12-23
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-12-23
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
CVSS Score
10.0
EPSS Score
0.004
Published
2021-12-23
StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may allow an administrative user to escalate their privileges and modify settings in SANtricity System Manager.
CVSS Score
4.4
EPSS Score
0.001
Published
2021-12-23


Contact Us

Shodan ® - All rights reserved