CVE-2023-28716: OS Command Injection
Published Apr 27, 2023
·Updated
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Affected Software
2 affected components
mySCADA myPRO<=8.26.0
mySCADA Technologies myPRO: versions 8.26.0 and prior
Event History
Apr 27, 2023
CVE Published
via MITRE·10:11 PM
Data Sourced
via MITRE·10:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the mySCADA myPRO vulnerability?
The vulnerability ID for the mySCADA myPRO vulnerability is CVE-2023-28716.
2
What is the severity of CVE-2023-28716?
The severity of CVE-2023-28716 is high with a severity value of 8.8.
3
What is the affected software for CVE-2023-28716?
The affected software for CVE-2023-28716 is mySCADA myPRO versions 8.26.0 and prior.
4
How can an authenticated user exploit CVE-2023-28716?
An authenticated user can exploit CVE-2023-28716 by injecting arbitrary operating system commands through certain parameters.
5
Is there a fix available for CVE-2023-28716?
It is advised to update mySCADA myPRO to version 8.26.1 or later to mitigate CVE-2023-28716.