Description
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized SMS Transmission
Action: Immediate Patch
AI Analysis

Impact

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint that allows attackers to send SMS messages via a connected GSM modem. Through this flaw, an adversary with network access can submit any phone number and message, causing the device to transmit the specified SMS. Although the vulnerability does not provide code execution or direct system compromise, it enables the abuse of the networked modem for malicious messaging, phishing or toll‑fraud campaigns.

Affected Systems

This weakness affects mySCADA Technologies’ mySCADA myPRO Manager, specifically versions released prior to the 2.2 update that incorporated a fix. Older deployments that lack the patch are exposed to the unauthenticated SMS sending mechanism.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The flaw is listed as not present in the CISA KEV catalog. Attackers would most likely exploit the remote network‑accessible HTTP endpoint; no special privileges are required beyond connectivity to the device. As the vulnerability does not impact confidentiality or integrity of the host system, the primary risk lies in the unauthorized use of the modem for covert communications.

Generated by OpenCVE AI on September 16, 2026 at 20:35 UTC.

Remediation

Vendor Solution

mySCADA Technologies has addressed this issue in Version 2.2 and recommends that users update to the latest version. Users are notified in mySCADA Pro Manager about the availability of a new version if the device is connected to the internet. Otherwise, users can download the mySCADA Pro Manager from the webpage. https://www.myscada.org/downloads/mySCADAPROManager/


OpenCVE Recommended Actions

  • Apply the vendor‑supplied update to mySCADA Pro Manager version 2.2 or later
  • If an update cannot be applied immediately, disable the exposed notification gateway service or restrict its exposure to trusted networks
  • Configure firewall rules to block inbound traffic to the HTTP endpoint used for SMS delivery
  • Implement monitoring of outbound SMS activity to detect anomalous usage patterns

Generated by OpenCVE AI on September 16, 2026 at 20:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a phone number and message from a request and sending the specified SMS message. An unauthenticated attacker with network access to the notification gateway could exploit this vulnerability to send arbitrary SMS messages through the connected modem.
Title mySCADA myPRO Manager Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-16T18:11:13.093Z

Reserved: 2026-09-08T21:20:02.648Z

Link: CVE-2026-82567

cve-icon Vulnrichment

Updated: 2026-09-16T18:11:09.903Z

cve-icon NVD

Status : Received

Published: 2026-09-15T22:17:03.363

Modified: 2026-09-16T19:17:44.833

Link: CVE-2026-82567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T20:45:05Z

Weaknesses