Critical
CVSS: 9.3
mySCADA myPRO Manager
is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
Critical
CVSS: 10.0
The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information and upload files without the associated password.
Medium
CVSS: 5.1
mySCADA myPRO Manager
is vulnerable to cross-site request forgery (CSRF), which could allow
an attacker to obtain sensitive information. An attacker would need to
trick the victim in to visiting an attacker-controlled website.
Critical
CVSS: 9.2
mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain sensitive information.