← back
CVE-2025-24865criticalCWE-306

mySCADA myPRO Manager Missing Authentication for Critical Function

43Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 10epss 7.0%
from disclosure to weapon0 days
Published on NVDFeb 13
metasploitFeb 13
exploitation probability
7.0%top 6% of all CVEs
observed exploitation
nono source reports it
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
mySCADA · myPRO Manager