VYPR

myPRO

by Scada Lts

CVEs (16)

  • CVE-2025-20061CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.00

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

  • CVE-2025-20014CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.00

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

  • CVE-2024-4708Jul 2, 2024
    risk 0.00cvss epss 0.00

    mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

  • CVE-2021-33013May 13, 2022
    risk 0.00cvss epss 0.00

    mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.

  • CVE-2021-33009May 13, 2022
    risk 0.00cvss epss 0.00

    mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system.

  • CVE-2021-33005May 13, 2022
    risk 0.00cvss epss 0.00

    mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.

  • CVE-2021-27505May 13, 2022
    risk 0.00cvss epss 0.00

    mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information.

  • CVE-2022-0999Apr 11, 2022
    risk 0.00cvss epss 0.00

    An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.

  • CVE-2021-43985Dec 23, 2021
    risk 0.00cvss epss 0.00

    An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.

  • CVE-2021-43989Dec 23, 2021
    risk 0.00cvss epss 0.00

    mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously retrieved password hashes.

  • CVE-2021-43981Dec 23, 2021
    risk 0.00cvss epss 0.00

    mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-44453Dec 23, 2021
    risk 0.00cvss epss 0.00

    mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.

  • CVE-2021-43984Dec 23, 2021
    risk 0.00cvss epss 0.00

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-22657Dec 23, 2021
    risk 0.00cvss epss 0.00

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-43987Dec 23, 2021
    risk 0.00cvss epss 0.00

    An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.

  • CVE-2021-23198Dec 23, 2021
    risk 0.00cvss epss 0.00

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.