CVE-2025-23411: mySCADA myPRO Manager Cross-Site Request Forgery
Published Feb 13, 2025
·Updated
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
Affected Software
2 affected componentsFixes available
: mySCADA myPRO Manager<1.4
1.4
mySCADA myPRO<1.4
Remediation
Information
mySCADA recommends users update to myPRO Manager v1.4 https://www.myscada.org/downloads/mySCADAPROManager/
Event History
Feb 13, 2025
CVE Published
via MITRE·09:33 PM
Data Sourced
via MITRE·09:33 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23411?
CVE-2025-23411 has been classified as a medium severity vulnerability due to the risk of cross-site request forgery.
2
How do I fix CVE-2025-23411?
To fix CVE-2025-23411, update mySCADA myPRO Manager to the latest version that mitigates the CSRF vulnerability.
3
What does CVE-2025-23411 affect?
CVE-2025-23411 affects mySCADA myPRO Manager versions up to but not including 1.4.
4
What type of attack does CVE-2025-23411 enable?
CVE-2025-23411 enables attackers to perform cross-site request forgery attacks to obtain sensitive information.
5
Who is the vendor associated with CVE-2025-23411?
The vendor associated with CVE-2025-23411 is mySCADA.