mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information and upload files without the associated password.
No advisories yet.
Solution
mySCADA recommends users update to myPRO Manager v1.4 https://www.myscada.org/downloads/mySCADAPROManager/
Workaround
No workaround given by the vendor.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 04 Mar 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Myscada
Myscada mypro |
|
| CPEs | cpe:2.3:a:myscada:mypro:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Myscada
Myscada mypro |
Fri, 14 Feb 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Feb 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password. | |
| Title | mySCADA myPRO Manager Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-14T15:47:26.772Z
Reserved: 2025-02-11T00:04:11.893Z
Link: CVE-2025-24865
Updated: 2025-02-14T15:38:00.733Z
Status : Analyzed
Published: 2025-02-13T22:15:12.613
Modified: 2025-03-04T20:59:05.417
Link: CVE-2025-24865
No data.
OpenCVE Enrichment
No data.