CVE-2023-28384: OS Command Injection
Published Apr 27, 2023
·Updated
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Affected Software
2 affected components
mySCADA myPRO<=8.26.0
mySCADA Technologies myPRO: versions 8.26.0 and prior
Event History
Apr 27, 2023
CVE Published
via MITRE·10:09 PM
Data Sourced
via MITRE·10:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-28384?
CVE-2023-28384 has a high severity rating due to its potential for authenticated users to inject arbitrary operating system commands.
2
How do I fix CVE-2023-28384?
To fix CVE-2023-28384, upgrade mySCADA myPRO to version 8.27.0 or later, which addresses this vulnerability.
3
Who is affected by CVE-2023-28384?
CVE-2023-28384 affects users of mySCADA myPRO versions 8.26.0 and prior.
4
What type of vulnerability is CVE-2023-28384?
CVE-2023-28384 is a command injection vulnerability that allows attackers to execute arbitrary operating system commands.
5
Can unprivileged users exploit CVE-2023-28384?
No, only authenticated users can exploit CVE-2023-28384 due to the requirement of valid user credentials.