Myscada Mydesigner vulnerabilities
2 known vulnerabilities affecting myscada/mydesigner.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2021-43555P3HIGHCVSS 7.8≤ 8.20.0≥ All, ≤ 8.20.02021-11-19
CVE-2021-43555 [HIGH] CWE-23 CVE-2021-43555: mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported proj
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in remote code execution.
nvd
CVE-2021-41578P3HIGHCVSS 7.8≤ 8.20.02021-10-04
CVE-2021-41578 [HIGH] CWE-22 CVE-2021-41578: mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files.
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
nvd