mySCADA myPRO 8.20.0

CPE Details

mySCADA myPRO 8.20.0
8.20.0
2021-12-28
15h09 +00:00
2022-01-21
19h58 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:myscada:mypro:8.20.0:*:*:*:*:*:*:*

Informations

Vendor

myscada

Product

mypro

Version

8.20.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-4708 2024-07-02 23h06 +00:00 mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
9.3
Critical
CVE-2023-28400 2023-04-27 22h18 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
High
CVE-2023-28716 2023-04-27 22h11 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
High
CVE-2023-28384 2023-04-27 22h09 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
High
CVE-2023-29169 2023-04-27 22h03 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
High
CVE-2023-29150 2023-04-27 22h01 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
High
CVE-2022-2234 2022-08-24 15h15 +00:00 An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
9.9
Critical
CVE-2022-0999 2022-04-11 19h38 +00:00 An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
8.8
High
CVE-2021-43985 2021-12-23 19h48 +00:00 An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
9.8
Critical
CVE-2021-43989 2021-12-23 19h48 +00:00 mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
7.5
High
CVE-2021-43981 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critical
CVE-2021-44453 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
10
Critical
CVE-2021-43984 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critical
CVE-2021-22657 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critical
CVE-2021-43987 2021-12-23 19h48 +00:00 An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
9.8
Critical
CVE-2021-23198 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critical