Show filters
36 Total Results
Displaying 1-10 of 36
Sort by:
Attacker Value
Unknown
CVE-2025-25067
Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager
is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
0
Attacker Value
Unknown
CVE-2025-24865
Disclosure Date: February 13, 2025 (last updated February 14, 2025)
The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information and upload files without the associated password.
0
Attacker Value
Unknown
CVE-2025-23411
Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager
is vulnerable to cross-site request forgery (CSRF), which could allow
an attacker to obtain sensitive information. An attacker would need to
trick the victim in to visiting an attacker-controlled website.
0
Attacker Value
Unknown
CVE-2025-22896
Disclosure Date: February 13, 2025 (last updated February 14, 2025)
mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2025-20061
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
0
Attacker Value
Unknown
CVE-2025-20014
Disclosure Date: January 29, 2025 (last updated January 30, 2025)
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
0
Attacker Value
Unknown
CVE-2024-52034
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
0
Attacker Value
Unknown
CVE-2024-50054
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
0
Attacker Value
Unknown
CVE-2024-47407
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
0
Attacker Value
Unknown
CVE-2024-47138
Disclosure Date: November 22, 2024 (last updated January 05, 2025)
The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.
0