A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 22:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands. | |
Title | mySCADA myPRO OS Command Injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2024-11-22T22:15:03.490Z
Updated: 2024-11-22T22:15:03.490Z
Reserved: 2024-11-13T20:44:28.680Z
Link: CVE-2024-47407
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-11-22T23:15:05.347
Modified: 2024-11-22T23:15:05.347
Link: CVE-2024-47407
Redhat
No data.