mySCADA myPRO Command Injection
CVE-2022-2234

9.9CRITICAL

Key Information:

Vendor
CVE Published:
24 August 2022

Summary

An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.

Affected Version(s)

mySCADA myPRO <= 8.26.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marlon Luis Petry reported this vulnerability to CISA.
.