mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
The vulnerability results from improper validation or sanitization of input data passed to system functions in mySCADA myPRO Manager (CWE-78). An attacker can send a specially crafted network request containing malicious system commands that are executed directly by the host operating system. The attack does not require any privileges or user interaction, making it particularly dangerous in industrial environments exposed to the network.
An attacker can gain full control over the operating system of the host running mySCADA myPRO Manager, including the ability to read and modify data, install malicious software, and disrupt industrial processes.
Patches available from the manufacturer should be applied according to the references. Updates can be downloaded from the manufacturer's website (https://www.myscada.org/downloads/mySCADAPROManager/). Additionally, it is recommended to isolate ICS/SCADA systems from public networks, use a firewall, and restrict network access to the system only to trusted hosts.
mySCADA myPRO Manager — versions indicated in the manufacturer's references and in the CISA ICS-CERT advisory (ICSA-25-044-16)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMyscada Mypro
APPMyscada< 1.4
Related vulnerabilities
mySCADA myPRO Manager — przechowywanie poświadczeń w postaci jawnej (cleartext)
Brak uwierzytelnienia w panelu administracyjnym mySCADA myPRO Manager
mySCADA myPRO — hardcoded password umożliwiający zdalne wykonanie kodu
Command Injection w mySCADA myPRO umożliwiający wykonanie poleceń OS
Command injection w mySCADA myPRO przez parametr wysyłania e-mail