PT-2024-8761 · Myscada · Myscada Mypro Manager+1
Michael Heinzl
·
Published
2024-11-21
·
Updated
2025-01-04
·
CVE-2024-47138
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
mySCADA myPRO versions (affected versions not specified)
mySCADA myPRO Manager versions (affected versions not specified)
Description
The issue is related to a lack of authentication for a critical function used in the operating system command. This can allow a remote attacker to bypass the authentication process. The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.
Recommendations
For mySCADA myPRO, consider restricting access to the administrative interface to minimize the risk of exploitation.
For mySCADA myPRO Manager, restrict access to the administrative interface to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Myscada Mypro
Myscada Mypro Manager