Myscada develops a focused line of industrial control and supervisory software products centered on MyPro and MyDesigner, which serve operational technology environments where vulnerability exposure carries outsized consequence. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value nature of control-system access and the appeal of these products to adversaries targeting industrial assets. The exposure recurs persistently through command-injection variants (OS command injection and general command injection), path-traversal conditions, and hard-coded or bypassable authentication mechanisms—weakness classes endemic to legacy control software that often prioritizes functionality and availability over input validation and credential management. Defenders operating these products should treat security updates as operationally urgent and restrict network access to authenticated, properly isolated management interfaces; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myscada over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28384HIGH mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | Apr 27, 2023 | 8.8 | 61 | NO | YES |
CVE-2022-2234HIGH An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. | Aug 24, 2022 | 8.8 | 52 | NO | NO |
CVE-2018-11311CRITICAL A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files | May 20, 2018 | 9.1 | 48 | NO | YES |
CVE-2025-24865CRITICAL The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information an | Feb 13, 2025 | 9.8 | 45 | NO | YES |
CVE-2021-43555HIGH mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. Thi | Nov 19, 2021 | 7.8 | 44 | NO | NO |
CVE-2023-28400HIGH mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | Apr 27, 2023 | 8.8 | 37 | NO | NO |
CVE-2025-22896HIGH mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain sensitive information. | Feb 13, 2025 | 7.5 | 34 | NO | YES |
CVE-2024-4708CRITICAL mySCADA myPRO
uses a hard-coded password which could allow an attacker to remotely execute code on the affected device. | Jul 2, 2024 | 9.8 | 31 | NO | NO |
CVE-2025-25067CRITICAL mySCADA myPRO Manager
is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands. | Feb 13, 2025 | 9.8 | 30 | NO | NO |
CVE-2021-44453CRITICAL mySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitrary operating system commands. | Dec 23, 2021 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myscada.
Media articles that mention a CVE ID that affects a product developed by Myscada — matched by CVE ID, not by vendor name.