CVE-2021-43984: mySCADA myPRO
Published Dec 23, 2021
·Updated
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
Affected Software
2 affected components
mySCADA myPRO<=8.20.0
mySCADA myPRO<=8.20.0
Remediation
Information
mySCADA recommends users upgrade to Version 8.22.0 or higher. For more information, contact mySCADA technical support.
Event History
Dec 23, 2021
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-43984?
CVE-2021-43984 is considered a high severity vulnerability due to the potential for arbitrary operating system command injection.
2
How do I fix CVE-2021-43984?
To fix CVE-2021-43984, upgrade mySCADA myPRO to version 8.21.0 or later, which addresses this vulnerability.
3
What versions of mySCADA myPRO are affected by CVE-2021-43984?
CVE-2021-43984 affects mySCADA myPRO versions 8.20.0 and earlier.
4
What type of vulnerability is CVE-2021-43984?
CVE-2021-43984 is a command injection vulnerability that allows attackers to execute arbitrary operating system commands.
5
Can CVE-2021-43984 be exploited remotely?
Yes, CVE-2021-43984 can be exploited remotely if the vulnerable version of mySCADA myPRO is accessible over the network.