CRITICAL🇵🇱 Wersja polska

CVE-2025-22896

CVSS 9.2v4.0pub. 2025-02-13upd. 2025-03-04

mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.

🤖 AI Analysis
How it works

The mySCADA myPRO Manager application stores authentication data (e.g., usernames and passwords) in plaintext — without encryption or proper protection (CWE-312: Cleartext Storage of Sensitive Information). An attacker who gains access to configuration files, application memory, or network traffic can read these credentials without any additional cryptographic effort. The vulnerability is remotely accessible, requires no authentication or user interaction.

Impact

An attacker can obtain credentials stored by the application and subsequently use them for unauthorized access to SCADA systems and related industrial infrastructure, which may lead to serious breaches of confidentiality of system and process data.

Mitigation & patch

Apply patches available from the vendor according to the references. It is recommended to download the updated version from the vendor's website (https://www.myscada.org/downloads/mySCADAPROManager/) and review the CISA recommendations described in advisory ICSA-25-044-16. Additionally, it is recommended to isolate SCADA systems from public networks, restrict access to configuration files, and monitor access to sensitive resources.

Who is affected

mySCADA myPRO Manager — versions indicated in vendor references (CISA ICS Advisory ICSA-25-044-16)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Myscada Mypro

    APP
    Myscada
    < 1.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-24865CRITICAL10.0PL ✓same product

Brak uwierzytelnienia w panelu administracyjnym mySCADA myPRO Manager

CVE-2025-25067CRITICAL9.3PL ✓same product

Command Injection w mySCADA myPRO Manager — zdalne wykonanie poleceń OS

CVE-2024-4708CRITICAL9.3PL ✓same product

mySCADA myPRO — hardcoded password umożliwiający zdalne wykonanie kodu

CVE-2022-2234CRITICAL9.9PL ✓same product

Command Injection w mySCADA myPRO umożliwiający wykonanie poleceń OS

CVE-2021-43981CRITICAL10.0PL ✓same product

Command injection w mySCADA myPRO przez parametr wysyłania e-mail