Vulnerabilities
8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-3746 | The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or o The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite files. NVD description · AI analysis pending | 6.8 | <1% |
| — | ||
| CVE-2022-3263 | The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modif The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2022-2897 +1 in the same advisory: …2898 | Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation.. NVD description · AI analysis pending | 7.8 group max | <1% |
| — | ||
| CVE-2022-2896 | Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file. Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file. NVD description · AI analysis pending | 7.8 | <1% |
| — |