CVE-2024-50054: mySCADA myPRO Path Traversal
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50054?
CVE-2024-50054 is classified as a high severity vulnerability due to potential unauthorized access to sensitive files.
How do I fix CVE-2024-50054?
To fix CVE-2024-50054, ensure that the application properly validates and sanitizes user-controlled filename parameters to prevent path traversal.
What types of attacks can CVE-2024-50054 facilitate?
CVE-2024-50054 can facilitate path traversal attacks, allowing attackers to access arbitrary files on the system.
Which software is affected by CVE-2024-50054?
CVE-2024-50054 affects the mySCADA myPRO Manager software.
What should I do if I am using a vulnerable version of mySCADA myPRO?
If using a vulnerable version of mySCADA myPRO, it is recommended to apply security patches as they are made available by the vendor.