First published: Fri Nov 22 2024(Updated: )
The administrative interface listens by default on all interfaces on a TCP port and does not require authentication when being accessed.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
mySCADA myPRO Manager |
mySCADA recommends updating to the latest versions: * mySCADA PRO Manager 1.3 https://www.myscada.org/resources/ * mySCADA PRO Runtime 9.2.1 https://www.myscada.org/resources/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47138 is rated as critical due to the lack of authentication and exposure of the administrative interface.
To mitigate CVE-2024-47138, configure the administrative interface to bind only to the localhost and require authentication to access the interface.
CVE-2024-47138 affects the mySCADA myPRO Manager software.
Yes, CVE-2024-47138 can lead to unauthorized access since the administrative interface does not require authentication.
The implications of CVE-2024-47138 include potential exposure and manipulation of sensitive user data due to unrestricted access.