mySCADA myPRO Improper Authentication
CVE-2024-45369

8.1HIGH

Key Information:

Vendor
Myscada
Vendor
CVE Published:
22 November 2024

Summary

A vulnerability exists in the web application due to the implementation of a weak authentication mechanism. This flaw allows unauthorized requests to bypass standard verification checks, potentially enabling attackers to gain access to sensitive resources without proper credentials. Ensuring robust authentication procedures is crucial to prevent unauthorized access and maintain the integrity of system resources.

Affected Version(s)

myPRO Manager 0 < 1.3

myPRO Runtime 0 < 9.2.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.
CVE-2024-45369 : mySCADA myPRO Improper Authentication | SecurityVulnerability.io