CVE-2025-20061: mySCADA myPRO Manager OS Command Injection
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20061?
CVE-2025-20061 is considered a significant vulnerability as it allows attackers to execute arbitrary commands on vulnerable systems.
How do I fix CVE-2025-20061?
To fix CVE-2025-20061, update mySCADA myPRO Manager to version 1.3 or mySCADA myPRO Runtime to version 9.2.1 or higher.
What systems are affected by CVE-2025-20061?
The affected systems include mySCADA myPRO Manager versions below 1.3 and mySCADA myPRO Runtime versions below 9.2.1.
Can CVE-2025-20061 be exploited remotely?
Yes, CVE-2025-20061 can potentially be exploited remotely through crafted POST requests.
What type of attacks can be executed through CVE-2025-20061?
CVE-2025-20061 can allow attackers to execute arbitrary commands, potentially leading to unauthorized system control.