CVE-2023-28400: OS Command Injection
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-28400.
What is the severity of CVE-2023-28400?
The severity of CVE-2023-28400 is high with a severity value of 8.8.
What is the affected software?
The affected software is mySCADA myPRO versions 8.26.0 and prior.
What is the description of CVE-2023-28400?
CVE-2023-28400 is a vulnerability in mySCADA myPRO versions 8.26.0 and prior that allows an authenticated user to inject arbitrary operating system commands.
How can an authenticated user exploit this vulnerability?
An authenticated user can exploit CVE-2023-28400 by injecting arbitrary operating system commands.
Is there a fix available for CVE-2023-28400?
Currently, there is no information available about a fix for CVE-2023-28400. It is recommended to follow the guidance provided by the software vendor or security advisory.
Where can I find more information about CVE-2023-28400?
You can find more information about CVE-2023-28400 at the following reference: https://www.cisa.gov/news-events/ics-advisories/icsa-23-096-06