ZDI-CAN-23546: ZDI-24-1226: mySCADA myPRO Hard-Coded Credentials Remote Code Execution Vulnerability
Published Sep 13, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of mySCADA myPRO. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2024-4708.
Affected Software
1 affected component
mySCADA myPRO
Event History
Sep 13, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23546?
The severity of ZDI-CAN-23546 is rated at 9.8 on the CVSS scale.
2
What software is affected by ZDI-CAN-23546?
The vulnerable software affected by ZDI-CAN-23546 is mySCADA myPRO.
3
Can ZDI-CAN-23546 be exploited without authentication?
Yes, ZDI-CAN-23546 can be exploited without any authentication required.
4
What type of vulnerability is ZDI-CAN-23546?
ZDI-CAN-23546 is a remote code execution vulnerability.
5
What is the CVE associated with ZDI-CAN-23546?
The CVE associated with ZDI-CAN-23546 is CVE-2024-4708.