Systems for controlling large-scale industrial processes over a vast geographic area are known as SCADA (supervisory control and data acquisition) systems (such as energy distribution plants). As well as Supervisory Computers, SCADA systems also include Programmable Logic Controllers (PLCs) and Remote Transmission Units (RTUs), two of the most important components (RTUs). Local administration of more particular sub-processes is performed by both PLCs and RTUs. Sensors and actuators on PLCs receive and transmit data to and from other SCADA system components. Connected sensors, such as PLCs and RTUs, provide plant managers with real-time data they may use to make vital choices. For human review and control, SCADA operations and data elements are given to supervisors via Human Machine Interfaces (HMIs). Considering their many uses, it’s no surprise that SCADA systems may be found in a wide variety of industrial settings and infrastructures. Even within the confines of the data collection, the large range of sources and natures of these findings suggests that a wide range of vulnerabilities still exist across vendors. However, it is important to keep in mind that SCADA system vulnerabilities still regularly include simple problems like stack and buffer overflows, as well as information exposure. Attackers can run arbitrary code (RCE), disrupt services (DoS), or steal data by exploiting these flaws. It is important for SCADA system integrators to know where vulnerabilities may exist to deploy mitigations that will prevent exploitation and neutralize attacks. SCADA systems have a wide range of devices, sensors, and software to manage, which makes them more vulnerable to attack. As a means of assisting users in making decisions, HMIs make use of data gathered by sensors and machinery linked to SCADA systems. Security threats may target HMIs because of their function in SCADA systems and their ability to control or steal important information.