Machine-generated analysis · WAYSCloud LLM
Versions ≤ 2.1 of mySCADA myPRO Manager lack authentication for privileged functions, allowing unauthenticated access.
Context
mySCADA myPRO Manager is a management application for SCADA systems. The advisory states that the command API does not enforce authentication, enabling unauthenticated attackers to access privileged management functions and send arbitrary SMS messages. The vendor has released version 2.2 that addresses these issues. Deployment is reported worldwide across multiple critical infrastructure sectors.
Operator considerations
- Check: Verify the installed myPRO Manager version is 2.1 or earlier.
- Isolate: Restrict network access to the command API to trusted hosts.
- Patch: Upgrade to version 2.2 or later as recommended by the vendor.
- Log: Monitor for unauthenticated API calls and SMS gateway usage.
Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.
The following versions of mySCADA myPRO Manager are affected:
mySCADA myPRO Manager
Read the full advisory on CISA →