CRITICAL🇵🇱 Wersja polska

CVE-2024-4708

CVSS 9.3v4.0pub. 2024-07-02upd. 2024-11-21

mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.

🤖 AI Analysis
How it works

The mySCADA myPRO software contains a static hardcoded password that cannot be changed by the user in the standard way. An attacker who knows this password can authenticate to the system without knowing the correct credentials. After gaining access, remote code execution (RCE) on the device is possible, without the need for any privileges or user interaction.

Impact

An attacker can remotely execute arbitrary code on the vulnerable device, leading to complete loss of confidentiality, integrity, and availability of the system. In the context of SCADA industrial systems, this can result in disruption or takeover of control over industrial processes.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with references — details in CISA advisory ICSA-24-184-02 (https://www.cisa.gov/news-events/ics-advisories/icsa-24-184-02) and on the mySCADA manufacturer's website.

Who is affected

mySCADA myPRO — versions indicated in manufacturer references (CISA advisory ICSA-24-184-02)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Myscada Mypro

    APP
    Myscada
    < 8.31.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-22896CRITICAL9.2PL ✓same product

mySCADA myPRO Manager — przechowywanie poświadczeń w postaci jawnej (cleartext)

CVE-2025-25067CRITICAL9.3PL ✓same product

Command Injection w mySCADA myPRO Manager — zdalne wykonanie poleceń OS

CVE-2025-24865CRITICAL10.0PL ✓same product

Brak uwierzytelnienia w panelu administracyjnym mySCADA myPRO Manager

CVE-2022-2234CRITICAL9.9PL ✓same product

Command Injection w mySCADA myPRO umożliwiający wykonanie poleceń OS

CVE-2021-43981CRITICAL10.0PL ✓same product

Command injection w mySCADA myPRO przez parametr wysyłania e-mail