CVE-2021-22657 CRITICAL

CVE-2021-22657: mySCADA myPRO

Vendor Myscada
Product myPRO
Weakness CWE-78
Published December 23, 2021
Last update September 17, 2024

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.

Key dates

02Disclosure timeline

December 23, 2021 CVE published
September 17, 2024 Record updated