mySCADA myPRO 7

CPE Details

mySCADA myPRO 7
7
2019-07-30
11h26 +00:00
2019-07-30
11h26 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:myscada:mypro:7:*:*:*:*:*:*:*

Informations

Vendor

myscada

Product

mypro

Version

7

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-4708 2024-07-02 23h06 +00:00 mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
9.3
Critique
CVE-2023-28400 2023-04-27 22h18 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
Haute
CVE-2023-28716 2023-04-27 22h11 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
Haute
CVE-2023-28384 2023-04-27 22h09 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
Haute
CVE-2023-29169 2023-04-27 22h03 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
Haute
CVE-2023-29150 2023-04-27 22h01 +00:00 mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
8.8
Haute
CVE-2022-2234 2022-08-24 15h15 +00:00 An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
9.9
Critique
CVE-2021-33013 2022-05-13 15h19 +00:00 mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
8.2
Haute
CVE-2021-33009 2022-05-13 15h19 +00:00 mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.
7.5
Haute
CVE-2021-33005 2022-05-13 15h18 +00:00 mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.
7.5
Haute
CVE-2021-27505 2022-05-13 15h17 +00:00 mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information.
7.5
Haute
CVE-2022-0999 2022-04-11 19h38 +00:00 An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
8.8
Haute
CVE-2021-43985 2021-12-23 19h48 +00:00 An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
9.8
Critique
CVE-2021-43989 2021-12-23 19h48 +00:00 mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
7.5
Haute
CVE-2021-43981 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critique
CVE-2021-44453 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
10
Critique
CVE-2021-43984 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critique
CVE-2021-22657 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critique
CVE-2021-43987 2021-12-23 19h48 +00:00 An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
9.8
Critique
CVE-2021-23198 2021-12-23 19h48 +00:00 mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
10
Critique
CVE-2017-12730 2017-10-06 02h00 +00:00 An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated privileges.
7.8
Haute