CVE-2023-29169: OS Command Injection
Published Apr 27, 2023
·Updated
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Affected Software
2 affected components
mySCADA myPRO<=8.26.0
mySCADA Technologies myPRO: versions 8.26.0 and prior
Event History
Apr 27, 2023
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-29169?
CVE-2023-29169 is categorized as a critical vulnerability due to the potential for arbitrary operating system command injection.
2
How do I fix CVE-2023-29169?
To remediate CVE-2023-29169, upgrade mySCADA myPRO to version 8.27.0 or later.
3
What are the potential impacts of exploiting CVE-2023-29169?
Exploitation of CVE-2023-29169 could allow an authenticated attacker to execute arbitrary commands on the system.
4
Which versions of myPRO are affected by CVE-2023-29169?
myPRO versions 8.26.0 and prior are affected by CVE-2023-29169.
5
Who is vulnerable to CVE-2023-29169?
Any organization using mySCADA myPRO versions 8.26.0 and earlier is vulnerable to CVE-2023-29169.