Scada Lts
Products
6- 29 CVEs
- 23 CVEs
- 4 CVEs
- 3 CVEs
- 2 CVEs
- 1 CVE
Recent CVEs
54| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24865 | Cri | 0.69 | 10.0 | 0.07 | Feb 13, 2025 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password. | ||
| CVE-2022-2234 | Cri | 0.68 | 9.9 | 0.41 | Aug 24, 2022 | An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. | ||
| CVE-2021-44453 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands. | ||
| CVE-2021-43984 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2021-43981 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2021-23198 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2021-22657 | Cri | 0.65 | 10.0 | 0.01 | Dec 23, 2021 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | ||
| CVE-2026-19656 | Cri | 0.64 | 9.9 | 0.00 | Aug 12, 2026 | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code… | ||
| CVE-2025-25067 | Cri | 0.64 | 9.8 | 0.02 | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands. | ||
| CVE-2025-20061 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. | ||
| CVE-2025-20014 | Cri | 0.64 | 9.8 | 0.01 | Jan 29, 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system. | ||
| CVE-2024-4708 | Cri | 0.64 | 9.8 | 0.01 | Jul 2, 2024 | mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. | ||
| CVE-2023-28384 | Hig | 0.64 | 8.8 | 0.45 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | ||
| CVE-2022-41976 | Cri | 0.64 | 9.9 | 0.02 | Apr 10, 2023 | An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile. | ||
| CVE-2021-43987 | Cri | 0.64 | 9.8 | 0.01 | Dec 23, 2021 | An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface. | ||
| CVE-2018-11311 | Cri | 0.63 | 9.1 | 0.16 | May 20, 2018 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials. | ||
| CVE-2025-22896 | Hig | 0.59 | 8.6 | 0.03 | Feb 13, 2025 | mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information. | ||
| CVE-2023-28400 | Hig | 0.59 | 8.8 | 0.25 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | ||
| CVE-2021-43985 | Cri | 0.59 | 9.1 | 0.02 | Dec 23, 2021 | An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization. | ||
| CVE-2023-28716 | Hig | 0.58 | 8.8 | 0.04 | Apr 27, 2023 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. |
- risk 0.69cvss 10.0epss 0.07
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
- risk 0.68cvss 9.9epss 0.41
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.65cvss 10.0epss 0.01
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
- risk 0.64cvss 9.9epss 0.00
ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code…
- risk 0.64cvss 9.8epss 0.02
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
- risk 0.64cvss 9.8epss 0.01
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
- risk 0.64cvss 8.8epss 0.45
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
- risk 0.64cvss 9.9epss 0.02
An privilege escalation issue was discovered in Scada-LTS 2.7.1.1 build 2948559113 allows remote attackers, authenticated in the application as a low-privileged user to change role (e.g., to administrator) by updating their user profile.
- risk 0.64cvss 9.8epss 0.01
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, which cannot be deleted or changed through the regular web interface.
- risk 0.63cvss 9.1epss 0.16
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
- risk 0.59cvss 8.6epss 0.03
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
- risk 0.59cvss 8.8epss 0.25
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
- risk 0.59cvss 9.1epss 0.02
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
- risk 0.58cvss 8.8epss 0.04
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.