Rapidscada develops an open-source industrial control system platform widely deployed in infrastructure and OT environments, concentrating its vulnerability exposure in a single product line. The recurring weakness classes—path traversal, permission mishandling, credential exposure, cross-site scripting, and sensitive-information leakage in error messages—reflect the authentication, access control, and web-interface demands of an ICS product serving both operator and administrative functions, with a meaningful share of disclosures reaching serious severity. Defenders should inventory Rapidscada instances in operational networks and prioritize patching for web-facing administrative interfaces; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rapidscada over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21764CRITICAL In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
| Feb 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2020-22722HIGH Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by | Aug 14, 2020 | 7.8 | 25 | NO | NO |
CVE-2018-5313HIGH A vulnerability allows local attackers to escalate privilege on Rapid Scada 5.5.0 because of weak C:\SCADA permissions. The specific flaw exists within the access control that is s | Mar 8, 2018 | 7.8 | 25 | NO | NO |
CVE-2024-21852HIGH In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking ro | Feb 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-22016HIGH In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.
| Feb 2, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-47221HIGH CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password. | Sep 22, 2024 | 7.5 | 21 | NO | NO |
CVE-2022-44153MEDIUM Rapid Software LLC Rapid SCADA 5.8.4 is vulnerable to Cross Site Scripting (XSS). | Dec 7, 2022 | 6.1 | 21 | NO | NO |
CVE-2024-22096MEDIUM In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific command, allowing them t | Feb 2, 2024 | 6.5 | 17 | NO | NO |
CVE-2024-21869MEDIUM In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local acce | Feb 2, 2024 | 5.5 | 17 | NO | NO |
CVE-2024-21866MEDIUM In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it receives a specific ma | Feb 2, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rapidscada.
Media articles that mention a CVE ID that affects a product developed by Rapidscada — matched by CVE ID, not by vendor name.