Impact
The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint that allows attackers to send SMS messages via a connected GSM modem. Through this flaw, an adversary with network access can submit any phone number and message, causing the device to transmit the specified SMS. Although the vulnerability does not provide code execution or direct system compromise, it enables the abuse of the networked modem for malicious messaging, phishing or toll‑fraud campaigns.
Affected Systems
This weakness affects mySCADA Technologies’ mySCADA myPRO Manager, specifically versions released prior to the 2.2 update that incorporated a fix. Older deployments that lack the patch are exposed to the unauthenticated SMS sending mechanism.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, and the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The flaw is listed as not present in the CISA KEV catalog. Attackers would most likely exploit the remote network‑accessible HTTP endpoint; no special privileges are required beyond connectivity to the device. As the vulnerability does not impact confidentiality or integrity of the host system, the primary risk lies in the unauthorized use of the modem for covert communications.
OpenCVE Enrichment