First published: Thu Dec 23 2021(Updated: )
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
mySCADA myPRO Manager | <=8.20.0 | |
mySCADA myPRO Manager | <=8.20.0 |
mySCADA recommends users upgrade to Version 8.22.0 or higher. For more information, contact mySCADA technical support.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44453 has been classified as a high-severity vulnerability due to its potential to allow arbitrary command injection.
To mitigate CVE-2021-44453, users should upgrade to version 8.20.1 or later of the mySCADA myPRO software.
CVE-2021-44453 affects mySCADA myPRO versions up to and including 8.20.0.
Yes, CVE-2021-44453 can potentially be exploited remotely if the vulnerable debug interface is exposed.
The exploitation of CVE-2021-44453 may lead to unauthorized access and control over the affected systems.