Show filters
36 Total Results
Displaying 21-30 of 36
Sort by:
Attacker Value
Unknown

CVE-2021-43987

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
Attacker Value
Unknown

CVE-2021-43984

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
Attacker Value
Unknown

CVE-2021-22657

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
Attacker Value
Unknown

CVE-2021-43985

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
Attacker Value
Unknown

CVE-2021-43989

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.
Attacker Value
Unknown

CVE-2021-43981

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
Attacker Value
Unknown

CVE-2021-44453

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
Attacker Value
Unknown

CVE-2021-43555

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in remote code execution.
Attacker Value
Unknown

CVE-2021-41578

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
Attacker Value
Unknown

CVE-2021-33013

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.