CVE-2025-24865

Severity CVSS v4.0:
CRITICAL
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
13/02/2025
Last modified:
04/03/2025

Description

The administrative web interface of <br /> mySCADA myPRO Manager<br /> <br /> can be accessed without authentication <br /> which could allow an unauthorized attacker to retrieve sensitive <br /> information and upload files without the associated password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:myscada:mypro:*:*:*:*:*:*:*:* 1.4 (excluding)