ZeroHour

Vulnerabilities

8 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-3746
The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or o

The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite files.

NVD description · AI analysis pending
6.8<1%
  • measuresoft scadapro server
CVE-2022-3263
The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modif

The security descriptor of Measuresoft ScadaPro Server version 6.7 has inconsistent permissions, which could allow a local user with limited privileges to modify the service binary path and start malicious commands with SYSTEM privileges.

NVD description · AI analysis pending
7.8<1%
  • measuresoft scadapro server
CVE-2022-2897
+1 in the same advisory: …2898
Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access;

Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation..

NVD description · AI analysis pending
7.8
group max
<1%
  • measuresoft scadapro client
  • measuresoft scadapro server
CVE-2022-2896
+3 in the same advisory: …2892 …2895 …2894
Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.

Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file.

NVD description · AI analysis pending
7.8<1%
  • measuresoft scadapro server