mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
The mySCADA myPRO software contains a static hardcoded password that cannot be changed by the user in the standard way. An attacker who knows this password can authenticate to the system without knowing the correct credentials. After gaining access, remote code execution (RCE) on the device is possible, without the need for any privileges or user interaction.
An attacker can remotely execute arbitrary code on the vulnerable device, leading to complete loss of confidentiality, integrity, and availability of the system. In the context of SCADA industrial systems, this can result in disruption or takeover of control over industrial processes.
Patches available from the manufacturer should be applied in accordance with references — details in CISA advisory ICSA-24-184-02 (https://www.cisa.gov/news-events/ics-advisories/icsa-24-184-02) and on the mySCADA manufacturer's website.
mySCADA myPRO — versions indicated in manufacturer references (CISA advisory ICSA-24-184-02)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMyscada Mypro
APPMyscada< 8.31.0
Related vulnerabilities
mySCADA myPRO Manager — przechowywanie poświadczeń w postaci jawnej (cleartext)
Command Injection w mySCADA myPRO Manager — zdalne wykonanie poleceń OS
Brak uwierzytelnienia w panelu administracyjnym mySCADA myPRO Manager
Command Injection w mySCADA myPRO umożliwiający wykonanie poleceń OS
Command injection w mySCADA myPRO przez parametr wysyłania e-mail