CVE-2021-22657: mySCADA myPRO
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22657?
CVE-2021-22657 is considered a critical vulnerability due to its potential to allow arbitrary operating system command injection.
How do I fix CVE-2021-22657?
To mitigate CVE-2021-22657, upgrade mySCADA myPRO to version 8.21.0 or later to ensure the API password injection feature is secured.
What are the potential impacts of CVE-2021-22657?
An attacker exploiting CVE-2021-22657 could execute arbitrary commands on the operating system, leading to data breaches or system compromise.
Which versions of mySCADA myPRO are affected by CVE-2021-22657?
CVE-2021-22657 affects mySCADA myPRO versions 8.20.0 and prior.
Is there a workaround for CVE-2021-22657?
As a workaround for CVE-2021-22657, it is recommended to restrict external access to the API until the software can be updated.