CVE-2025-20061

Published Jan 29, 2025

Last updated 2 months ago

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-20061 is an operating system command injection vulnerability affecting mySCADA myPRO products, specifically myPRO Manager and myPRO Runtime. The vulnerability stems from the improper neutralization of special elements within POST requests sent to a specific port when email information is included. Successful exploitation of CVE-2025-20061 could allow a remote attacker to execute arbitrary commands on the affected system. This is possible due to the failure to properly sanitize user inputs, which opens the door to command injection. The vulnerability can be mitigated by updating to mySCADA PRO Manager 1.3 and mySCADA PRO Runtime 9.2.1.

Description
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
Source
ics-cert@hq.dhs.gov
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

ics-cert@hq.dhs.gov
CWE-78

Social media

Hype score
Not currently trending
  1. 🚨 Critical SCADA Flaws — Researchers uncovered 2 critical vulnerabilities (CVSS 9.3) in mySCADA myPRO, allowing attackers to execute system commands & hijack operations. 🔹 CVE-2025-20014 & CVE-2025-20061 🔹 Full Industrial Network Compromise Possible https://t.co/iFtz5

    @achi_tech

    20 Mar 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Investigadores han descubierto 2 vulnerabilidades críticas (CVSS 9.3) en mySCADA myPRO, que permiten a los atacantes ejecutar comandos del sistema y tomar el control de operaciones industriales. 🔹 CVE-2025-20014 y CVE-2025-20061 🔹 Posible compromiso total de redes… https:

    @Cyph3R_CyberSec

    19 Mar 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Critical flaws in mySCADA myPRO could let attackers execute arbitrary commands, risking operations and finances. Patches are essential to combat CVE-2025-20014 and CVE-2025-20061. ⚠️ #mySCADA #IndustrialSecurity #USA link: https://t.co/sCU2WEKb83 https://t.co/PtxXdo71an

    @TweetThreatNews

    19 Mar 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Critical SCADA Flaws — Researchers uncovered 2 critical vulnerabilities (CVSS 9.3) in mySCADA myPRO, allowing attackers to execute system commands & hijack operations. 🔹 CVE-2025-20014 & CVE-2025-20061 🔹 Full Industrial Network Compromise Possible https://t.co/o3iS

    @TheHackersNews

    19 Mar 2025

    32200 Impressions

    75 Retweets

    168 Likes

    39 Bookmarks

    3 Replies

    3 Quotes

  5. 🚨 Critical SCADA Vulnerabilities Alert 🚨 PRODAFT has identified two critical (9.3 CVSSv4) OS command injection flaws in mySCADA myPRO Manager, risking industrial control networks. ⚠ CVE-2025-20014 & CVE-2025-20061 ➡ Remote code execution ➡ Affects myPRO Manager <1.3 &a

    @PRODAFT

    18 Mar 2025

    1508 Impressions

    2 Retweets

    23 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️ Vulnerability Alert: mySCADA myPRO Command Injection Remote Code Execution Vulnerability 📅 Timeline: Disclosure: 2025-01-23, Patch: 2025-01-23 📌 Attribution: Reported by Mehmet INCE (@mdisec) from https://t.co/CcKunYQilf 🆔cveId: CVE-2025-20061 📊baseScore: 9.8… https://t.

    @syedaquib77

    19 Feb 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Actively exploited CVE : CVE-2025-20061

    @transilienceai

    4 Feb 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  8. CVE-2025-20061 mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execu… https://t.co/mGUjDT7kLB

    @CVEnew

    29 Jan 2025

    344 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. [CVE-2025-20061: CRITICAL] Vulnerability alert: mySCADA myPRO is susceptible to a POST request vulnerability, allowing attackers to execute commands on the system. #cybersecurity#cybersecurity,#vulnerability https://t.co/v12iHYhxSd https://t.co/8MrFbg5vlt

    @CveFindCom

    29 Jan 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes