← Vulnerability feed

Vulnerability record · CVE-2023-28384 · published 27 April 2023

CVE-2023-28384: mySCADA myPRO OS Command Injection via Exposed Parameters

Myscada · Mypro

mySCADA myPRO versions 8.26.0 and prior contain parameters that allow an authenticated user to inject arbitrary operating system commands. This is a CWE-78 OS command injection flaw in an industrial HMI/SCADA product, so successful exploitation can compromise the host running myPRO and potentially reach connected control systems.

8.8 CVSS 3.1 High EPSS 45% · top 1.3% CWE-78 · OS command injection
8.8CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability and high EPSS (98.7th percentile) make this a serious risk despite requiring authentication and not being in KEV.

What it is

mySCADA myPRO versions 8.26.0 and prior contain parameters that allow an authenticated user to inject arbitrary operating system commands. This is a CWE-78 OS command injection flaw in an industrial HMI/SCADA product, so successful exploitation can compromise the host running myPRO and potentially reach connected control systems.

Impact

An attacker with valid credentials can execute arbitrary OS commands on the myPRO host, gaining full control of that system (high confidentiality, integrity and availability impact). From there they could disrupt or manipulate industrial processes managed by the HMI.

Attack surface

Reachable over the network (AV:N) with low attack complexity and no user interaction, but it requires a low-privileged authenticated account (PR:L). The vulnerable parameters are the injection point.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.4481 (98.7th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade mySCADA myPRO to a version later than 8.26.0 if available; treat patching as the first action.
  • If immediate upgrade is not possible, restrict network access to myPRO management interfaces to trusted hosts and segments.
  • Enforce least privilege and strong unique credentials for myPRO accounts; remove or disable unused accounts.
  • Monitor and validate any input passed to myPRO parameters, and apply vendor or CISA ICS advisory guidance for hardening.
  • Segment the myPRO host from broader IT and control networks to limit lateral movement after compromise.

Detection

  • Monitor myPRO host process creation for unexpected child processes spawned by the application (e.g., cmd.exe, /bin/sh, powershell).
  • Alert on anomalous outbound network connections from the myPRO server to untrusted hosts.
  • Audit authentication logs for unusual or off-hours logins to myPRO, especially from new source IPs.
  • Review application and OS logs for command strings or shell metacharacters in myPRO parameter inputs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.cisa.gov/news-events/ics-advisories/icsa-23-096-06 Third Party AdvisoryUS Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-096-06 Third Party AdvisoryUS Government Resource

Track CVE-2023-28384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-24865Myscada mypro missing authentication for critical function vulnerabilityThe administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrie…EPSS 7.2%9.8CVE-2021-43981Myscada mypro os command injection vulnerabilitymySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands thro…EPSS 1.2%9.8CVE-2021-43984Myscada mypro os command injection vulnerabilitymySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating s…EPSS 1.2%9.8CVE-2021-43985Myscada mypro authentication bypass via alternate path vulnerabilityAn unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.EPSS 1.5%9.8CVE-2021-43987Myscada mypro vulnerabilityAn additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and prior that is not exposed through the web interface, …EPSS 1.2%9.8CVE-2021-44453Myscada mypro os command injection vulnerabilitymySCADA myPRO: Versions 8.20.0 and prior has a vulnerable debug interface which includes a ping utility, which may allow an attacker to inject arbitr…EPSS 1.4%9.8CVE-2021-23198Myscada mypro os command injection vulnerabilitymySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating…EPSS 1.2%9.8CVE-2021-22657Myscada mypro os command injection vulnerabilitymySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary opera…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2023-28384), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.