PT-2018-10633 · Myscada · Myscada Mypro

Pedro Sampaio

·

Publicado

2018-05-28

·

Atualizado

2018-06-29

·

CVE-2018-11517

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions mySCADA myPRO version 7
Description The issue allows remote attackers to discover all ProjectIDs in a project. This is achieved by sending specific requests to the TCP port 11010, using the "prj" parameter with values ranging from 870000 to 875000 in "t=0&rq=0" requests.
Recommendations For mySCADA myPRO version 7, restrict access to TCP port 11010 to minimize the risk of exploitation. Avoid using the prj parameter in requests to this port until the issue is resolved.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11517

Produtos afetados

Myscada Mypro