Vulnerability record · CVE-2023-28384 · published 27 April 2023
CVE-2023-28384: mySCADA myPRO OS Command Injection via Exposed Parameters
Myscada · Mypro
mySCADA myPRO versions 8.26.0 and prior contain parameters that allow an authenticated user to inject arbitrary operating system commands. This is a CWE-78 OS command injection flaw in an industrial HMI/SCADA product, so successful exploitation can compromise the host running myPRO and potentially reach connected control systems.
Description
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS (98.7th percentile) make this a serious risk despite requiring authentication and not being in KEV.
What it is
mySCADA myPRO versions 8.26.0 and prior contain parameters that allow an authenticated user to inject arbitrary operating system commands. This is a CWE-78 OS command injection flaw in an industrial HMI/SCADA product, so successful exploitation can compromise the host running myPRO and potentially reach connected control systems.
Impact
An attacker with valid credentials can execute arbitrary OS commands on the myPRO host, gaining full control of that system (high confidentiality, integrity and availability impact). From there they could disrupt or manipulate industrial processes managed by the HMI.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires a low-privileged authenticated account (PR:L). The vulnerable parameters are the injection point.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.4481 (98.7th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade mySCADA myPRO to a version later than 8.26.0 if available; treat patching as the first action.
- If immediate upgrade is not possible, restrict network access to myPRO management interfaces to trusted hosts and segments.
- Enforce least privilege and strong unique credentials for myPRO accounts; remove or disable unused accounts.
- Monitor and validate any input passed to myPRO parameters, and apply vendor or CISA ICS advisory guidance for hardening.
- Segment the myPRO host from broader IT and control networks to limit lateral movement after compromise.
Detection
- Monitor myPRO host process creation for unexpected child processes spawned by the application (e.g., cmd.exe, /bin/sh, powershell).
- Alert on anomalous outbound network connections from the myPRO server to untrusted hosts.
- Audit authentication logs for unusual or off-hours logins to myPRO, especially from new source IPs.
- Review application and OS logs for command strings or shell metacharacters in myPRO parameter inputs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-096-06 | Third Party AdvisoryUS Government Resource |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-096-06 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-28384 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-28384), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.