CVE-2025-24865: mySCADA myPRO Manager Missing Authentication for Critical Function
The administrative web interface of mySCADA myPRO Manager
can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24865?
CVE-2025-24865 is considered a significant security vulnerability due to the ability for unauthorized access to sensitive information.
How do I fix CVE-2025-24865?
To fix CVE-2025-24865, ensure that authentication is enabled for the administrative web interface of mySCADA myPRO Manager.
What versions of mySCADA myPRO Manager are affected by CVE-2025-24865?
CVE-2025-24865 affects all versions of mySCADA myPRO Manager prior to 1.4.
What could an attacker do if they exploit CVE-2025-24865?
An attacker could retrieve sensitive information and potentially upload files without authentication if they exploit CVE-2025-24865.
How can I secure mySCADA myPRO Manager against CVE-2025-24865?
Securing mySCADA myPRO Manager against CVE-2025-24865 involves configuring proper access controls and ensuring that the administrative interface requires authentication.