CRITICAL🇵🇱 Wersja polska

CVE-2025-25067

CVSS 9.3v4.0pub. 2025-02-13upd. 2025-04-23

mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.

🤖 AI Analysis
How it works

The vulnerability results from improper validation or sanitization of input data passed to system functions in mySCADA myPRO Manager (CWE-78). An attacker can send a specially crafted network request containing malicious system commands that are executed directly by the host operating system. The attack does not require any privileges or user interaction, making it particularly dangerous in industrial environments exposed to the network.

Impact

An attacker can gain full control over the operating system of the host running mySCADA myPRO Manager, including the ability to read and modify data, install malicious software, and disrupt industrial processes.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Updates can be downloaded from the manufacturer's website (https://www.myscada.org/downloads/mySCADAPROManager/). Additionally, it is recommended to isolate ICS/SCADA systems from public networks, use a firewall, and restrict network access to the system only to trusted hosts.

Who is affected

mySCADA myPRO Manager — versions indicated in the manufacturer's references and in the CISA ICS-CERT advisory (ICSA-25-044-16)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Myscada Mypro

    APP
    Myscada
    < 1.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-22896CRITICAL9.2PL ✓same product

mySCADA myPRO Manager — przechowywanie poświadczeń w postaci jawnej (cleartext)

CVE-2025-24865CRITICAL10.0PL ✓same product

Brak uwierzytelnienia w panelu administracyjnym mySCADA myPRO Manager

CVE-2024-4708CRITICAL9.3PL ✓same product

mySCADA myPRO — hardcoded password umożliwiający zdalne wykonanie kodu

CVE-2022-2234CRITICAL9.9PL ✓same product

Command Injection w mySCADA myPRO umożliwiający wykonanie poleceń OS

CVE-2021-43981CRITICAL10.0PL ✓same product

Command injection w mySCADA myPRO przez parametr wysyłania e-mail