ZDI-25-088: mySCADA myPRO Command Injection Remote Code Execution Vulnerability
Published Feb 19, 2025
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of mySCADA myPRO. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2025-20061.
Affected Software
1 affected component
mySCADA myPRO
Event History
Feb 19, 2025
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-25-088?
ZDI-25-088 has a CVSS rating of 9.8, indicating critical severity.
2
How do I fix ZDI-25-088?
To mitigate ZDI-25-088, it is recommended to update mySCADA myPRO to the latest version provided by the vendor.
3
What kind of attacks can be executed due to ZDI-25-088?
ZDI-25-088 allows remote attackers to execute arbitrary code on affected installations without authentication.
4
Are there any prerequisites to exploit ZDI-25-088?
No, ZDI-25-088 can be exploited without any authentication, making it particularly dangerous.
5
Which software versions are affected by ZDI-25-088?
ZDI-25-088 affects all installations of mySCADA myPRO that have not been patched.