CVE-2022-0999: mySCADA myPRO Command Injection
Published Apr 11, 2022
·Updated
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
Affected Software
2 affected components
mySCADA myPRO<=8.25.0
mySCADA myPRO Versions 8.25.0 and prior
Remediation
Information
mySCADA recommends users upgrade to version 8.26 or higher. For more information, contact mySCADA technical support. mySCADA will also send security advice by email to all registered users.
Event History
Apr 11, 2022
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
RemedyDescriptionSeverityWeakness
Aug 2, 2024
Data Sourced
via ICS·11:55 PM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-0999?
CVE-2022-0999 is rated as a high severity vulnerability due to the potential for arbitrary command execution by an authenticated user.
2
How do I fix CVE-2022-0999?
To fix CVE-2022-0999, update mySCADA myPRO to version 8.25.1 or later.
3
What systems are affected by CVE-2022-0999?
CVE-2022-0999 affects mySCADA myPRO versions 8.25.0 and prior.
4
What type of vulnerability is CVE-2022-0999?
CVE-2022-0999 is classified as a command injection vulnerability.
5
Who is impacted by CVE-2022-0999?
Authenticated users of mySCADA myPRO versions 8.25.0 and before are at risk of exploitation due to CVE-2022-0999.