CVE-2026-82567
- EPSS 0.34%
- Veröffentlicht 15.09.2026 21:45:45
- Zuletzt bearbeitet 18.09.2026 19:35:57
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number a...
CVE-2026-73807
- EPSS 0.65%
- Veröffentlicht 15.09.2026 21:42:55
- Zuletzt bearbeitet 18.09.2026 19:35:57
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.
CVE-2025-35941
- EPSS 0.28%
- Veröffentlicht 11.06.2025 13:15:50
- Zuletzt bearbeitet 15.04.2026 00:35:42
A password is exposed locally.
CVE-2025-25067
- EPSS 1.63%
- Veröffentlicht 13.02.2025 22:15:12
- Zuletzt bearbeitet 23.04.2025 18:45:35
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
CVE-2025-24865
- EPSS 7.11%
- Veröffentlicht 13.02.2025 22:15:12
- Zuletzt bearbeitet 04.03.2025 20:59:05
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
CVE-2025-23411
- EPSS 0.58%
- Veröffentlicht 13.02.2025 22:15:11
- Zuletzt bearbeitet 04.03.2025 20:59:05
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
CVE-2025-22896
- EPSS 3.5%
- Veröffentlicht 13.02.2025 22:15:11
- Zuletzt bearbeitet 04.03.2025 20:59:05
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
CVE-2024-4708
- EPSS 1%
- Veröffentlicht 02.07.2024 23:15:10
- Zuletzt bearbeitet 21.11.2024 09:43:25
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
CVE-2023-29169
- EPSS 0.75%
- Veröffentlicht 27.04.2023 23:15:15
- Zuletzt bearbeitet 17.01.2025 18:15:22
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
CVE-2023-29150
- EPSS 0.75%
- Veröffentlicht 27.04.2023 23:15:15
- Zuletzt bearbeitet 17.01.2025 18:15:22
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.