HIGH
mySCADA myPRO Path Traversal
Published May 13, 2022
7.5
HIGHCVSS 3.1
EPSS 1.59%
Description
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<8.20.0
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
mySCADA recommends users apply update v8.20.0 or later.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-19726 Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-217-03 x_refsource_MISCThird Party AdvisoryUS Government Resource
- https://www.myscada.org/version-8-20-0-released-security-update x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-19726 | Advisory | |
| https://www.cisa.gov/uscert/ics/advisories/icsa-21-217-03 | x_refsource_MISCThird Party AdvisoryUS Government Resource | |
| https://www.myscada.org/version-8-20-0-released-security-update | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published May 13, 2022
Updated Apr 16, 2025
Reserved May 13, 2021
Link CVE-2021-33005
CISA Vulnrichment
Updated Apr 16, 2025
ENISA EUVD
EUVD-2021-19726 Assigner icscert
Published May 13, 2022
Updated Apr 16, 2025
Exploited since n/a
Link EUVD-2021-19726