myPRO Manager
by Scada Lts
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-24865 | Cri | 0.69 | 10.0 | 0.07 | Feb 13, 2025 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password. | ||
| CVE-2026-73807 | Cri | 0.64 | 9.8 | 0.01 | Sep 15, 2026 | The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions. | ||
| CVE-2025-25067 | Cri | 0.64 | 9.8 | 0.02 | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands. | ||
| CVE-2025-22896 | Hig | 0.59 | 8.6 | 0.04 | Feb 13, 2025 | mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information. | ||
| CVE-2026-82567 | Med | 0.41 | 6.3 | 0.00 | Sep 15, 2026 | The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and… | ||
| CVE-2025-23411 | Med | 0.41 | 6.3 | 0.01 | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website. |
- risk 0.69cvss 10.0epss 0.07
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
- risk 0.64cvss 9.8epss 0.01
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
- risk 0.64cvss 9.8epss 0.02
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
- risk 0.59cvss 8.6epss 0.04
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
- risk 0.41cvss 6.3epss 0.00
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and…
- risk 0.41cvss 6.3epss 0.01
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.