Vulnerabilities > Myscada > High

DATE CVE VULNERABILITY TITLE RISK
2022-04-11 CVE-2022-0999 OS Command Injection vulnerability in Myscada Mypro
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
network
low complexity
myscada CWE-78
8.8
2021-12-23 CVE-2021-43989 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Myscada Mypro 7/7.0.26
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
network
low complexity
myscada CWE-327
7.5
2021-11-19 CVE-2021-43555 Path Traversal vulnerability in Myscada Mydesigner
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload.
local
low complexity
myscada CWE-22
7.8
2021-10-04 CVE-2021-41578 Path Traversal vulnerability in Myscada Mydesigner
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files.
local
low complexity
myscada CWE-22
7.8
2017-10-06 CVE-2017-12730 Unquoted Search Path or Element vulnerability in Myscada Mypro 7/7.0.26
An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior.
local
low complexity
myscada CWE-428
7.8