Записи mySCADA
34 опубликованных записей вендора myscada.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 4 · 11,8 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-306 Missing Authentication for Critical Function2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
- CWE-287 Improper Authentication1
- CWE-288 Authentication Bypass Using an Alternate Path or Channel1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
34 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2024-47407Готовый эксплойт | mySCADA myPRO OS Command Injectionmyscada · mypro manager · CWE-78 | Критическая10,0 | — | 64,0 % | 22 нояб. 2024 г. |
48В плане | CVE-2023-28384Готовый эксплойт | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commanmyscada · mypro · CWE-78 | Высокая8,8 | — | 44,8 % | 27 апр. 2023 г. |
48В плане | CVE-2022-2234Эксплойта нет | mySCADA myPRO Command Injectionmyscada · mypro · CWE-77 | Высокая8,8 | — | 42,3 % | 24 авг. 2022 г. |
42В плане | CVE-2021-43555Эксплойта нет | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulmyscada · mydesigner · CWE-23 | Высокая7,8 | — | 38,2 % | 19 нояб. 2021 г. |
42В плане | CVE-2023-28400Эксплойта нет | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commanmyscada · mypro · CWE-78 | Высокая8,8 | — | 24,6 % | 27 апр. 2023 г. |
42В плане | CVE-2025-24865Готовый эксплойт | mySCADA myPRO Manager Missing Authentication for Critical Functionmyscada · mypro · CWE-306 | Критическая10,0 | — | 7,2 % | 13 февр. 2025 г. |
41В плане | CVE-2018-11311Proof of concept | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTmyscada · mypro · CWE-798 | Критическая9,1 | — | 15,2 % | 20 мая 2018 г. |
41В плане | CVE-2024-52034Эксплойта нет | mySCADA myPRO OS Command Injectionmyscada · mypro manager · CWE-78 | Критическая10,0 | — | 1,7 % | 22 нояб. 2024 г. |
39Наблюдать | CVE-2021-43985Эксплойта нет | An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.myscada · mypro · CWE-288 | Критическая9,8 | — | 1,5 % | 23 дек. 2021 г. |
39Наблюдать | CVE-2021-44453Эксплойта нет | mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to injemyscada · mypro · CWE-78 | Критическая9,8 | — | 1,4 % | 23 дек. 2021 г. |
39Наблюдать | CVE-2021-22657Эксплойта нет | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrmyscada · mypro · CWE-78 | Критическая9,8 | — | 1,2 % | 23 дек. 2021 г. |
39Наблюдать | CVE-2021-43981Эксплойта нет | mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commmyscada · mypro · CWE-78 | Критическая9,8 | — | 1,2 % | 23 дек. 2021 г. |
39Наблюдать | CVE-2021-43984Эксплойта нет | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary opmyscada · mypro · CWE-78 | Критическая9,8 | — | 1,2 % | 23 дек. 2021 г. |
39Наблюдать | CVE-2021-23198Эксплойта нет | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary myscada · mypro · CWE-78 | Критическая9,8 | — | 1,2 % | 23 дек. 2021 г. |
39Наблюдать | CVE-2021-43987Эксплойта нет | An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web inmyscada · mypro · CWE-912 | Критическая9,8 | — | 1,2 % | 23 дек. 2021 г. |
37Наблюдать | CVE-2025-22896Готовый эксплойт | mySCADA myPRO Manager Cleartext Storage of Sensitive Informationmyscada · mypro · CWE-312 | Критическая9,2 | — | 3,6 % | 13 февр. 2025 г. |
37Наблюдать | CVE-2025-25067Эксплойта нет | mySCADA myPRO Manager OS Command Injectionmyscada · mypro · CWE-78 | Критическая9,3 | — | 1,7 % | 13 февр. 2025 г. |
37Наблюдать | CVE-2024-4708Эксплойта нет | mySCADA myPRO Use of Hard-coded Passwordmyscada · mypro · CWE-259 | Критическая9,3 | — | 1,0 % | 2 июл. 2024 г. |
37Наблюдать | CVE-2024-47138Эксплойта нет | mySCADA myPRO Missing Authentication for Critical Functionmyscada · mypro manager · CWE-306 | Критическая9,3 | — | 0,8 % | 22 нояб. 2024 г. |
36Наблюдать | CVE-2023-28716Эксплойта нет | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commanmyscada · mypro · CWE-78 | Высокая8,8 | — | 4,5 % | 27 апр. 2023 г. |
36Наблюдать | CVE-2024-45369Эксплойта нет | mySCADA myPRO Improper Authenticationmyscada · mypro manager · CWE-287 | Критическая9,2 | — | 0,6 % | 22 нояб. 2024 г. |
35Наблюдать | CVE-2022-0999Эксплойта нет | mySCADA myPRO Command Injectionmyscada · mypro · CWE-77 | Высокая8,8 | — | 1,4 % | 11 апр. 2022 г. |
35Наблюдать | CVE-2023-29169Эксплойта нет | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commanmyscada · mypro · CWE-78 | Высокая8,8 | — | 0,7 % | 27 апр. 2023 г. |
35Наблюдать | CVE-2023-29150Эксплойта нет | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commanmyscada · mypro · CWE-78 | Высокая8,8 | — | 0,7 % | 27 апр. 2023 г. |
34Наблюдать | CVE-2021-41578Эксплойта нет | mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files.myscada · mydesigner · CWE-22 | Высокая7,8 | — | 10,8 % | 4 окт. 2021 г. |
- CVE-2024-4740759В плане
mySCADA myPRO OS Command Injection
КритическаяCVSS 10,0Готовый эксплойтEPSS 64 %myscada · mypro manager22 нояб. 2024 г.
- CVE-2023-2838448В плане
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system comman
ВысокаяCVSS 8,8Готовый эксплойтEPSS 45 %myscada · mypro27 апр. 2023 г.
- CVE-2022-223448В плане
mySCADA myPRO Command Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 42 %myscada · mypro24 авг. 2022 г.
- CVE-2021-4355542В плане
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vul
ВысокаяCVSS 7,8Эксплойта нетEPSS 38 %myscada · mydesigner19 нояб. 2021 г.
- CVE-2023-2840042В плане
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system comman
ВысокаяCVSS 8,8Эксплойта нетEPSS 25 %myscada · mypro27 апр. 2023 г.
- CVE-2025-2486542В плане
mySCADA myPRO Manager Missing Authentication for Critical Function
КритическаяCVSS 10,0Готовый эксплойтEPSS 7 %myscada · mypro13 февр. 2025 г.
- CVE-2018-1131141В плане
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FT
КритическаяCVSS 9,1Proof of conceptEPSS 15 %myscada · mypro20 мая 2018 г.
- CVE-2024-5203441В плане
mySCADA myPRO OS Command Injection
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %myscada · mypro manager22 нояб. 2024 г.
- CVE-2021-4398539Наблюдать
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %myscada · mypro23 дек. 2021 г.
- CVE-2021-4445339Наблюдать
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inje
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %myscada · mypro23 дек. 2021 г.
- CVE-2021-2265739Наблюдать
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitr
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %myscada · mypro23 дек. 2021 г.
- CVE-2021-4398139Наблюдать
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system comm
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %myscada · mypro23 дек. 2021 г.
- CVE-2021-4398439Наблюдать
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary op
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %myscada · mypro23 дек. 2021 г.
- CVE-2021-2319839Наблюдать
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %myscada · mypro23 дек. 2021 г.
- CVE-2021-4398739Наблюдать
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web in
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %myscada · mypro23 дек. 2021 г.
- CVE-2025-2289637Наблюдать
mySCADA myPRO Manager Cleartext Storage of Sensitive Information
КритическаяCVSS 9,2Готовый эксплойтEPSS 4 %myscada · mypro13 февр. 2025 г.
- CVE-2025-2506737Наблюдать
mySCADA myPRO Manager OS Command Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %myscada · mypro13 февр. 2025 г.
- CVE-2024-470837Наблюдать
mySCADA myPRO Use of Hard-coded Password
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %myscada · mypro2 июл. 2024 г.
- CVE-2024-4713837Наблюдать
mySCADA myPRO Missing Authentication for Critical Function
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %myscada · mypro manager22 нояб. 2024 г.
- CVE-2023-2871636Наблюдать
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system comman
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %myscada · mypro27 апр. 2023 г.
- CVE-2024-4536936Наблюдать
mySCADA myPRO Improper Authentication
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %myscada · mypro manager22 нояб. 2024 г.
- CVE-2022-099935Наблюдать
mySCADA myPRO Command Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %myscada · mypro11 апр. 2022 г.
- CVE-2023-2916935Наблюдать
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system comman
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %myscada · mypro27 апр. 2023 г.
- CVE-2023-2915035Наблюдать
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system comman
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %myscada · mypro27 апр. 2023 г.
- CVE-2021-4157834Наблюдать
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files.
ВысокаяCVSS 7,8Эксплойта нетEPSS 11 %myscada · mydesigner4 окт. 2021 г.