VYPR

myPRO Manager

by Scada Lts

CVEs (4)

  • CVE-2025-24865CriFeb 13, 2025
    risk 0.69cvss 10.0epss 0.07

    The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.

  • CVE-2025-25067CriFeb 13, 2025
    risk 0.64cvss 9.8epss 0.02

    mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

  • CVE-2025-22896HigFeb 13, 2025
    risk 0.59cvss 8.6epss 0.03

    mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.

  • CVE-2025-23411MedFeb 13, 2025
    risk 0.41cvss 6.3epss 0.01

    mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.