📦 Mypro

by Myscada

🔍 What is Mypro?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-24865

CRITICAL CVSS 10.0 Feb 13, 2025

CVE-2025-24865 allows unauthenticated access to the mySCADA myPRO Manager administrative web interface. Attackers can retrieve sensitive information and upload files without credentials. This affects ...

CVE-2024-4708

CRITICAL CVSS 9.8 Jul 2, 2024

CVE-2024-4708 is a critical vulnerability in mySCADA myPRO software where attackers can use a hard-coded password to gain unauthorized access and execute arbitrary code remotely. This affects all orga...

CVE-2021-43981

CRITICAL CVSS 10.0 Dec 23, 2021

CVE-2021-43981 is a critical OS command injection vulnerability in mySCADA myPRO versions 8.20.0 and earlier. Attackers can execute arbitrary operating system commands through email parameters, potent...

CVE-2021-43985

CRITICAL CVSS 9.1 Dec 23, 2021

CVE-2021-43985 allows an unauthenticated remote attacker to access mySCADA myPRO systems without authentication or authorization, potentially leading to unauthorized control or data exposure. Affected...

CVE-2021-44453

CRITICAL CVSS 10.0 Dec 23, 2021

CVE-2021-44453 is a critical command injection vulnerability in mySCADA myPRO's debug interface that allows attackers to execute arbitrary operating system commands through the ping utility. This affe...

CVE-2021-22657

CRITICAL CVSS 10.0 Dec 23, 2021

This vulnerability allows remote attackers to execute arbitrary operating system commands on mySCADA myPRO systems by injecting malicious commands through the API password parameter. It affects all ve...

CVE-2025-22896

HIGH CVSS 8.6 Feb 13, 2025

mySCADA myPRO Manager stores credentials in cleartext, allowing attackers to read sensitive authentication data. This affects all systems running vulnerable versions of mySCADA myPRO Manager software....

CVE-2023-29169

HIGH CVSS 8.8 Apr 27, 2023

This vulnerability allows authenticated users to inject arbitrary operating system commands in mySCADA myPRO versions 8.26.0 and prior. Attackers with valid credentials can execute commands with the p...

CVE-2023-28384

HIGH CVSS 8.8 Apr 27, 2023

This vulnerability allows authenticated users in mySCADA myPRO systems to inject arbitrary operating system commands through vulnerable parameters. It affects industrial control systems using mySCADA ...

CVE-2023-28716

HIGH CVSS 8.8 Apr 27, 2023

This vulnerability allows authenticated users of mySCADA myPRO versions 8.26.0 and prior to inject arbitrary operating system commands through vulnerable parameters. This could lead to complete system...

CVE-2021-33009

HIGH CVSS 7.5 May 13, 2022

CVE-2021-33009 allows unauthenticated remote attackers to upload arbitrary files to the mySCADA myPRO system file system. This affects mySCADA myPRO versions prior to 8.20.0, potentially enabling atta...

CVE-2021-27505

HIGH CVSS 7.5 May 13, 2022

CVE-2021-27505 is an information disclosure vulnerability in mySCADA myPRO software where unauthorized users can access sensitive directory listings. This exposes internal system information that coul...

CVE-2021-43989

HIGH CVSS 7.5 Dec 23, 2021

mySCADA myPRO versions 8.20.0 and prior store passwords using the weak MD5 hashing algorithm, which allows attackers who obtain password hashes to crack them relatively easily. This affects industrial...

CVE-2025-23411

MEDIUM CVSS 6.3 Feb 13, 2025

mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), allowing attackers to trick authenticated users into performing unintended actions that could expose sensitive information. Th...