Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Myscada

First CVE: Oct 6, 2017Active for: 9 yearsTotal CVEs: 30
62.2
VTI Score
TOP TARGET

Myscada develops a focused line of industrial control and supervisory software products centered on MyPro and MyDesigner, which serve operational technology environments where vulnerability exposure carries outsized consequence. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value nature of control-system access and the appeal of these products to adversaries targeting industrial assets. The exposure recurs persistently through command-injection variants (OS command injection and general command injection), path-traversal conditions, and hard-coded or bypassable authentication mechanisms—weakness classes endemic to legacy control software that often prioritizes functionality and availability over input validation and credential management. Defenders operating these products should treat security updates as operationally urgent and restrict network access to authenticated, properly isolated management interfaces; live severity, exploitation, and exposure figures are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
8.5
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Myscada over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2017
8 years ago
Most Recent CVE
Jun 11, 2025
408 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-28384HIGH
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Apr 27, 20238.861NOYES
CVE-2022-2234HIGH
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
Aug 24, 20228.852NONO
CVE-2018-11311CRITICAL
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files
May 20, 20189.148NOYES
CVE-2025-24865CRITICAL
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information an
Feb 13, 20259.845NOYES
CVE-2021-43555HIGH
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. Thi
Nov 19, 20217.844NONO
CVE-2023-28400HIGH
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
Apr 27, 20238.837NONO
CVE-2025-22896HIGH
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
Feb 13, 20257.534NOYES
CVE-2024-4708CRITICAL
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
Jul 2, 20249.831NONO
CVE-2025-25067CRITICAL
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
Feb 13, 20259.830NONO
CVE-2021-44453CRITICAL
mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands.
Dec 23, 20219.830NONO
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
10%
53%
37%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (13.3%)
Network26 (86.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None27 (90.0%)
Unknown0 (0.0%)
Required3 (10.0%)
Privileges Required
Low9 (30.0%)
High0 (0.0%)
None21 (70.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
10.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Myscada.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Myscada — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Myscada's Products

View all 3 CNAs →

Top CWEs