VYPR
Vendor

Scada Lts

Products
6
CVEs
54
Across products
62
Status
Private

Products

6

Recent CVEs

54
View all 54 CVEs →
  • CVE-2025-24865CriFeb 13, 2025
    risk 0.69cvss 10.0epss 0.07

    The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.

  • CVE-2022-2234CriAug 24, 2022
    risk 0.68cvss 9.9epss 0.41

    An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.

  • CVE-2021-44453CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.

  • CVE-2021-43984CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-43981CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-23198CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2021-22657CriDec 23, 2021
    risk 0.65cvss 10.0epss 0.01

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

  • CVE-2026-19656CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code…

  • CVE-2025-25067CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.02

    mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

  • CVE-2025-20061CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

  • CVE-2025-20014CriJan 29, 2025
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.

  • CVE-2024-4708CriJul 2, 2024
    risk 0.64cvss 9.8epss 0.01

    mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

  • CVE-2023-28384HigApr 27, 2023
    risk 0.64cvss 8.8epss 0.45

    mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

  • CVE-2022-41976CriApr 10, 2023
    risk 0.64cvss 9.9epss 0.02

    An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile.

  • CVE-2021-43987CriDec 23, 2021
    risk 0.64cvss 9.8epss 0.01

    An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.

  • CVE-2018-11311CriMay 20, 2018
    risk 0.63cvss 9.1epss 0.16

    A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.

  • CVE-2025-22896HigFeb 13, 2025
    risk 0.59cvss 8.6epss 0.03

    mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.

  • CVE-2023-28400HigApr 27, 2023
    risk 0.59cvss 8.8epss 0.25

    mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

  • CVE-2021-43985CriDec 23, 2021
    risk 0.59cvss 9.1epss 0.02

    An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.

  • CVE-2023-28716HigApr 27, 2023
    risk 0.58cvss 8.8epss 0.04

    mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.