First published: Fri Nov 22 2024(Updated: )
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
mySCADA myPRO Manager |
mySCADA recommends updating to the latest versions: * mySCADA PRO Manager 1.3 https://www.myscada.org/resources/ * mySCADA PRO Runtime 9.2.1 https://www.myscada.org/resources/
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47407 is rated as a critical vulnerability due to its potential to allow unauthenticated remote attackers to execute arbitrary operating system commands.
To fix CVE-2024-47407, update your myPRO Manager software to the latest version that addresses this vulnerability.
Any users of mySCADA myPRO Manager software may be impacted by CVE-2024-47407 if they have not applied the necessary security updates.
CVE-2024-47407 can be exploited through remote command injection attacks, allowing attackers to issue arbitrary commands on the affected system.
No, exploitation of CVE-2024-47407 does not require authentication, making it more dangerous to exposed systems.