PT-2018-10473 · Myscada · Myscada Mypro
Emreovunc
·
Published
2018-05-20
·
Updated
2018-06-26
·
CVE-2018-11311
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
mySCADA myPRO version 7
Description
The issue allows remote attackers to access the FTP server on port 2121, upload files, or list directories by using a hardcoded FTP username and password. The hardcoded credentials are
username set to 'myscada' and password set to 'Vikuk63' in the 'myscadagate.exe' file.Recommendations
For mySCADA myPRO version 7, consider changing the hardcoded FTP credentials to secure ones, and restrict access to the FTP server on port 2121 until a patch is available. As a temporary workaround, restrict the use of the 'myscadagate.exe' file to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Myscada Mypro