mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
The mySCADA myPRO Manager application stores authentication data (e.g., usernames and passwords) in plaintext — without encryption or proper protection (CWE-312: Cleartext Storage of Sensitive Information). An attacker who gains access to configuration files, application memory, or network traffic can read these credentials without any additional cryptographic effort. The vulnerability is remotely accessible, requires no authentication or user interaction.
An attacker can obtain credentials stored by the application and subsequently use them for unauthorized access to SCADA systems and related industrial infrastructure, which may lead to serious breaches of confidentiality of system and process data.
Apply patches available from the vendor according to the references. It is recommended to download the updated version from the vendor's website (https://www.myscada.org/downloads/mySCADAPROManager/) and review the CISA recommendations described in advisory ICSA-25-044-16. Additionally, it is recommended to isolate SCADA systems from public networks, restrict access to configuration files, and monitor access to sensitive resources.
mySCADA myPRO Manager — versions indicated in vendor references (CISA ICS Advisory ICSA-25-044-16)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMyscada Mypro
APPMyscada< 1.4
Related vulnerabilities
Brak uwierzytelnienia w panelu administracyjnym mySCADA myPRO Manager
Command Injection w mySCADA myPRO Manager — zdalne wykonanie poleceń OS
mySCADA myPRO — hardcoded password umożliwiający zdalne wykonanie kodu
Command Injection w mySCADA myPRO umożliwiający wykonanie poleceń OS
Command injection w mySCADA myPRO przez parametr wysyłania e-mail