CVE-2023-29150: OS Command Injection
Published Apr 27, 2023
·Updated
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Affected Software
2 affected components
mySCADA myPRO<=8.26.0
mySCADA Technologies myPRO: versions 8.26.0 and prior
Event History
Apr 27, 2023
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-29150?
CVE-2023-29150 has a high severity rating due to its potential for arbitrary command injection by authenticated users.
2
How do I fix CVE-2023-29150?
To mitigate CVE-2023-29150, update myPRO to a version later than 8.26.0.
3
Which versions of myPRO are affected by CVE-2023-29150?
CVE-2023-29150 affects mySCADA myPRO versions 8.26.0 and prior.
4
Who is affected by CVE-2023-29150?
Any user running mySCADA myPRO versions 8.26.0 or earlier is potentially affected by CVE-2023-29150.
5
What type of attack can be performed due to CVE-2023-29150?
CVE-2023-29150 allows authenticated users to inject arbitrary operating system commands, potentially compromising system integrity.