AI description
CVE-2025-20061 is an operating system command injection vulnerability affecting mySCADA myPRO products, specifically myPRO Manager and myPRO Runtime. The vulnerability stems from the improper neutralization of special elements within POST requests sent to a specific port when email information is included. Successful exploitation of CVE-2025-20061 could allow a remote attacker to execute arbitrary commands on the affected system. This is possible due to the failure to properly sanitize user inputs, which opens the door to command injection. The vulnerability can be mitigated by updating to mySCADA PRO Manager 1.3 and mySCADA PRO Runtime 9.2.1.
- Description
- mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Received
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- ics-cert@hq.dhs.gov
- CWE-78
- Hype score
- Not currently trending
🚨 Critical SCADA Flaws — Researchers uncovered 2 critical vulnerabilities (CVSS 9.3) in mySCADA myPRO, allowing attackers to execute system commands & hijack operations. 🔹 CVE-2025-20014 & CVE-2025-20061 🔹 Full Industrial Network Compromise Possible https://t.co/iFtz5
@achi_tech
20 Mar 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Investigadores han descubierto 2 vulnerabilidades críticas (CVSS 9.3) en mySCADA myPRO, que permiten a los atacantes ejecutar comandos del sistema y tomar el control de operaciones industriales. 🔹 CVE-2025-20014 y CVE-2025-20061 🔹 Posible compromiso total de redes… https:
@Cyph3R_CyberSec
19 Mar 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical flaws in mySCADA myPRO could let attackers execute arbitrary commands, risking operations and finances. Patches are essential to combat CVE-2025-20014 and CVE-2025-20061. ⚠️ #mySCADA #IndustrialSecurity #USA link: https://t.co/sCU2WEKb83 https://t.co/PtxXdo71an
@TweetThreatNews
19 Mar 2025
16 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical SCADA Flaws — Researchers uncovered 2 critical vulnerabilities (CVSS 9.3) in mySCADA myPRO, allowing attackers to execute system commands & hijack operations. 🔹 CVE-2025-20014 & CVE-2025-20061 🔹 Full Industrial Network Compromise Possible https://t.co/o3iS
@TheHackersNews
19 Mar 2025
32200 Impressions
75 Retweets
168 Likes
39 Bookmarks
3 Replies
3 Quotes
🚨 Critical SCADA Vulnerabilities Alert 🚨 PRODAFT has identified two critical (9.3 CVSSv4) OS command injection flaws in mySCADA myPRO Manager, risking industrial control networks. ⚠ CVE-2025-20014 & CVE-2025-20061 ➡ Remote code execution ➡ Affects myPRO Manager <1.3 &a
@PRODAFT
18 Mar 2025
1508 Impressions
2 Retweets
23 Likes
3 Bookmarks
0 Replies
0 Quotes
⚠️ Vulnerability Alert: mySCADA myPRO Command Injection Remote Code Execution Vulnerability 📅 Timeline: Disclosure: 2025-01-23, Patch: 2025-01-23 📌 Attribution: Reported by Mehmet INCE (@mdisec) from https://t.co/CcKunYQilf 🆔cveId: CVE-2025-20061 📊baseScore: 9.8… https://t.
@syedaquib77
19 Feb 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2025-20061
@transilienceai
4 Feb 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-20061 mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execu… https://t.co/mGUjDT7kLB
@CVEnew
29 Jan 2025
344 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-20061: CRITICAL] Vulnerability alert: mySCADA myPRO is susceptible to a POST request vulnerability, allowing attackers to execute commands on the system. #cybersecurity#cybersecurity,#vulnerability https://t.co/v12iHYhxSd https://t.co/8MrFbg5vlt
@CveFindCom
29 Jan 2025
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes