CVE-2025-22896: mySCADA myPRO Manager Cleartext Storage of Sensitive Information
Published Feb 13, 2025
·Updated
mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
Affected Software
2 affected componentsFixes available
: mySCADA myPRO Manager<1.4
1.4
mySCADA myPRO<1.4
Remediation
Information
mySCADA recommends users update to myPRO Manager v1.4 https://www.myscada.org/downloads/mySCADAPROManager/
Event History
Feb 13, 2025
CVE Published
via MITRE·09:31 PM
Data Sourced
via MITRE·09:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-22896?
CVE-2025-22896 is considered a high severity vulnerability due to the exposure of sensitive credentials in cleartext.
2
How do I fix CVE-2025-22896?
To fix CVE-2025-22896, update mySCADA myPRO Manager to version 1.4 or higher which addresses the credential storage issue.
3
What impact does CVE-2025-22896 have on mySCADA myPRO Manager?
CVE-2025-22896 can lead to unauthorized access to sensitive information due to the storage of credentials in cleartext.
4
Is mySCADA myPRO Manager version 1.4 affected by CVE-2025-22896?
No, mySCADA myPRO Manager version 1.4 and above are not affected by CVE-2025-22896.
5
Who is affected by CVE-2025-22896?
Organizations using mySCADA myPRO Manager versions earlier than 1.4 are affected by CVE-2025-22896.