Impact
The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions, allowing an unauthenticated attacker with network access to perform management actions. This flaw provides the attacker with unauthorized control over the device, potentially leading to configuration changes, data manipulation, or service disruption. The weakness corresponds to improper privilege management.
Affected Systems
mySCADA Technologies' mySCADA myPRO product, including all builds prior to version 2.2. Users connected to the internet are notified by the Manager of the new version, while those offline must download the update manually from the vendor website.
Risk and Exploitability
The CVSS score of 9.3 signals a critical severity. The EPSS score of < 1% indicates a low likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Attackers can reach the vulnerable API over the network; no additional privileges or code execution are required, making it an accessible but low–probability threat for connected systems.
OpenCVE Enrichment