mySCADA myPRO Manager Missing Authentication for Critical Function
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 10epss 7.0%
from disclosure to weapon0 days
Published on NVDFeb 13
metasploitFeb 13
exploitation probability
7.0%top 6% of all CVEs
observed exploitation
nono source reports it
The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information and upload files without the associated password.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
mySCADA · myPRO Manager