mySCADA myPRO Manager

Summary

Successful exploitation of vulnerabilities in mySCADA myPRO Manager versions less than or equal to 2.1 could allow an attacker to gain access to privileged management functions or send arbitrary SMS messages through the connected GSM modem. The vulnerabilities stem from missing authorization for privileged functions and missing authentication for critical functions.

IFF Assessment

FOE

The identified vulnerabilities allow unauthenticated attackers to access privileged management functions and potentially send arbitrary SMS messages, posing a significant risk to operational technology systems.

Severity

9.8 Critical

The CVSS score of 9.8 reflects the critical severity of the vulnerabilities, particularly the ability for an unauthenticated attacker with network access to perform privileged management functions, indicating high exploitability and significant impact.

Defender Context

This alert highlights critical vulnerabilities in OT systems used in essential infrastructure, emphasizing the need for defenders to prioritize patching and hardening these environments. The ability for unauthenticated access to management functions is a severe risk that could lead to system compromise or disruption.

Read Full Story →