First published: Mon May 28 2018(Updated: )
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
mySCADA myPRO | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-11517.
The severity of CVE-2018-11517 is medium with a CVSS score of 5.3.
CVE-2018-11517 allows remote attackers to discover all ProjectIDs in a project by sending specific requests to TCP port 11010.
At the moment, there is no known fix for CVE-2018-11517. It is recommended to follow the vendor's security advisories for any updates or patches.
You can find more information about CVE-2018-11517 at the following references: [link1](https://github.com/EmreOvunc/mySCADA-myPRO-7-projectID-Disclosure), [link2](https://www.emreovunc.com/blog/en/mypro_enum_projectid.rb)