Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2025-25067

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
0
Attacker Value
Unknown

CVE-2025-24865

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
0
Attacker Value
Unknown

CVE-2025-23411

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
0
Attacker Value
Unknown

CVE-2025-22896

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2025-20061

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
0
Attacker Value
Unknown

CVE-2025-20014

Disclosure Date: January 29, 2025 (last updated January 30, 2025)
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
0
Attacker Value
Unknown

CVE-2024-52034

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
0
Attacker Value
Unknown

CVE-2024-50054

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
0
Attacker Value
Unknown

CVE-2024-47407

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
0
Attacker Value
Unknown

CVE-2024-47138

Disclosure Date: November 22, 2024 (last updated January 05, 2025)
The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.
0