Myscada
Myscada Mypro: vulnerabilidades y CVE
Myscada Mypro tiene 29 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 14 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses0
Críticas14
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-25067 | Crítica (9.3) | 1.7% | — | 13 feb 2025 | mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands. |
| CVE-2025-24865 | Crítica (10) | 7.2% | — | 13 feb 2025 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated… |
| CVE-2025-23411 | Media (5.1) | 0.60% | — | 13 feb 2025 | mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled… |
| CVE-2025-22896 | Crítica (9.2) | 3.6% | — | 13 feb 2025 | mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information. |
| CVE-2025-20061 | Crítica (9.3) | 1.3% | — | 29 ene 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. |
| CVE-2025-20014 | Crítica (9.3) | 1.3% | — | 29 ene 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. |
| CVE-2024-4708 | Crítica (9.3) | 1.00% | — | 2 jul 2024 | mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. |
| CVE-2023-29169 | Alta (8.8) | 0.75% | — | 27 abr 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. |
| CVE-2023-29150 | Alta (8.8) | 0.75% | — | 27 abr 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. |
| CVE-2023-28716 | Alta (8.8) | 4.5% | — | 27 abr 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. |
| CVE-2023-28400 | Alta (8.8) | 25% | — | 27 abr 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. |
| CVE-2023-28384 | Alta (8.8) | 45% | — | 27 abr 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. |
| CVE-2022-2234 | Alta (8.8) | 42% | — | 24 ago 2022 | An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. |
| CVE-2021-33013 | Alta (7.5) | 0.84% | — | 13 may 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information. |
| CVE-2021-33009 | Alta (7.5) | 1.3% | — | 13 may 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system. |
| CVE-2021-33005 | Alta (7.5) | 1.6% | — | 13 may 2022 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories. |
| CVE-2021-27505 | Alta (7.5) | 1.1% | — | 13 may 2022 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information. |
| CVE-2022-0999 | Alta (8.8) | 1.4% | — | 11 abr 2022 | An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior. |
| CVE-2021-44453 | Crítica (9.8) | 1.4% | — | 23 dic 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands. |
| CVE-2021-43989 | Alta (7.5) | 0.65% | — | 23 dic 2021 | mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes. |
| CVE-2021-43987 | Crítica (9.8) | 1.2% | — | 23 dic 2021 | An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface. |
| CVE-2021-43985 | Crítica (9.8) | 1.5% | — | 23 dic 2021 | An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization. |
| CVE-2021-43984 | Crítica (9.8) | 1.2% | — | 23 dic 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. |
| CVE-2021-43981 | Crítica (9.8) | 1.2% | — | 23 dic 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. |
| CVE-2021-23198 | Crítica (9.8) | 1.2% | — | 23 dic 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. |
| CVE-2021-22657 | Crítica (9.8) | 1.2% | — | 23 dic 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. |
| CVE-2018-11517 | Media (5.3) | 2.1% | — | 28 may 2018 | mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010. |
| CVE-2018-11311 | Crítica (9.1) | 15% | — | 20 may 2018 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these… |
| CVE-2017-12730 | Alta (7.8) | 0.73% | — | 6 oct 2017 | An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated… |