CVE-2025-24865
CVE-2025-24865
10.0
CriticalPublished:
Last updated:
Source:ics-cert@hq.dhs.gov
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- High
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
References
ics-cert@hq.dhs.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-16ics-cert@hq.dhs.gov
https://www.myscada.org/contacts/ics-cert@hq.dhs.gov
https://www.myscada.org/downloads/mySCADAPROManager/