Vulnerabilities > Myscada > Mypro > 7

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-0999 OS Command Injection vulnerability in Myscada Mypro 7/7.0.26/8.20.0
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
network
low complexity
myscada CWE-78
critical
9.0
2021-12-23 CVE-2021-22657 OS Command Injection vulnerability in Myscada Mypro 7/7.0.26
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada CWE-78
7.5
2021-12-23 CVE-2021-23198 OS Command Injection vulnerability in Myscada Mypro 7/7.0.26
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada CWE-78
7.5
2021-12-23 CVE-2021-43981 OS Command Injection vulnerability in Myscada Mypro 7/7.0.26
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada CWE-78
7.5
2021-12-23 CVE-2021-43984 OS Command Injection vulnerability in Myscada Mypro 7/7.0.26
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada CWE-78
7.5
2021-12-23 CVE-2021-43985 Authentication Bypass Using an Alternate Path or Channel vulnerability in Myscada Mypro 7/7.0.26
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
network
low complexity
myscada CWE-288
7.5
2021-12-23 CVE-2021-43987 Hidden Functionality vulnerability in Myscada Mypro 7/7.0.26
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
network
low complexity
myscada CWE-912
7.5
2021-12-23 CVE-2021-43989 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Myscada Mypro 7/7.0.26
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
network
low complexity
myscada CWE-327
7.5
2021-12-23 CVE-2021-44453 OS Command Injection vulnerability in Myscada Mypro 7/7.0.26
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
network
low complexity
myscada CWE-78
critical
10.0
2017-10-06 CVE-2017-12730 Unquoted Search Path or Element vulnerability in Myscada Mypro 7/7.0.26
An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior.
local
low complexity
myscada CWE-428
7.2