CVE-2021-23198: mySCADA myPRO
Published Dec 23, 2021
·Updated
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
Affected Software
2 affected components
mySCADA myPRO<=8.20.0
mySCADA myPRO<=8.20.0
Remediation
Information
mySCADA recommends users upgrade to Version 8.22.0 or higher. For more information, contact mySCADA technical support.
Event History
Dec 23, 2021
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-23198.
2
What is the severity of CVE-2021-23198?
CVE-2021-23198 has a severity rating of critical.
3
What is the affected software for CVE-2021-23198?
The affected software for CVE-2021-23198 is mySCADA myPRO versions 8.20.0 and prior.
4
What is the CWE ID for CVE-2021-23198?
CVE-2021-23198 has a CWE ID of 78.
5
How can an attacker exploit CVE-2021-23198?
An attacker can exploit CVE-2021-23198 by injecting arbitrary operating system commands through a specific parameter.