Known vulnerabilities in myPRO Runtime

Vendor: mySCADA
Software: myPRO Runtime
Software CPE: cpe:2.3:a:myscada:mypro_runtime:*:*:*:*:*:*:*:*
Total vulnerabilities: 7
Public exploits: 1
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting myPRO Runtime myPRO Runtime is affected by 7 known vulnerabilities: 6 high, 1 medium Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU103272 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-20014
CWE-78 High
No
No
9.2.1 24.01.2025 SB2025012405
#VU103271 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-20061
CWE-78 High
No
No
9.2.1 24.01.2025 SB2025012405
#VU100875 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-50054
CWE-22 Medium
No
No
9.2.1 25.11.2024 SB2024112514
#VU100874 - Missing Authentication for Critical Function
CVE-2024-47138
CWE-306 High
No
No
9.2.1 25.11.2024 SB2024112514
#VU100873 - Improper Authentication
CVE-2024-45369
CWE-287 High
No
No
9.2.1 25.11.2024 SB2024112514
#VU100872 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-52034
CWE-78 High
No
No
9.2.1 25.11.2024 SB2024112514
#VU100871 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-47407
CWE-78 High
Available
Exploited
9.2.1 25.11.2024 SB2024112514