Vulnerabilities > Myscada > Critical

DATE CVE VULNERABILITY TITLE RISK
2025-02-13 CVE-2025-24865 Missing Authentication for Critical Function vulnerability in Myscada Mypro
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
network
low complexity
myscada CWE-306
critical
9.8
2025-02-13 CVE-2025-25067 OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
network
low complexity
myscada CWE-78
critical
9.8
2024-07-02 CVE-2024-4708 Use of Hard-coded Credentials vulnerability in Myscada Mypro
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
network
low complexity
myscada CWE-798
critical
9.8
2021-12-23 CVE-2021-22657 Unspecified vulnerability in Myscada Mypro 7/7.0.26/8.20.0
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada
critical
9.8
2021-12-23 CVE-2021-23198 Unspecified vulnerability in Myscada Mypro 7/7.0.26/8.20.0
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada
critical
9.8
2021-12-23 CVE-2021-43981 Unspecified vulnerability in Myscada Mypro 7/7.0.26/8.20.0
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada
critical
9.8
2021-12-23 CVE-2021-43984 Unspecified vulnerability in Myscada Mypro 7/7.0.26/8.20.0
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
network
low complexity
myscada
critical
9.8
2021-12-23 CVE-2021-43985 Unspecified vulnerability in Myscada Mypro 7/7.0.26/8.20.0
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
network
low complexity
myscada
critical
9.8
2021-12-23 CVE-2021-43987 Unspecified vulnerability in Myscada Mypro 7/7.0.26/8.20.0
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
network
low complexity
myscada
critical
9.8
2021-12-23 CVE-2021-44453 Unspecified vulnerability in Myscada Mypro 7/7.0.26/8.20.0
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
network
low complexity
myscada
critical
9.8