CVE-2025-24865

Published Feb 13, 2025

Last updated 9 days ago

Overview

Description
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
Source
ics-cert@hq.dhs.gov
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

ics-cert@hq.dhs.gov
CWE-306

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. “mySCADA myPRO Manager”də kritik boşluqlar (CVE-2025-24865, CVE-2025-25067 ) aşkar olunub #ETX #certaz #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/zPLH8UzWJA

    @CERTAzerbaijan

    20 Feb 2025

    40 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 ALERTĂ - Vulnerabilități critice de securitate cibernetică identificate la nivelul unor produse mySCADA 💡 CVE-2025-24865 este o vulnerabilitate de securitate critică, clasificată drept Authentication Bypass, care afectează sistemele ce rulează software-ul mySCADA myPRO https

    @DNSC_RO

    19 Feb 2025

    76 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CVE-2025-24865 (CVSS 10): Critical mySCADA myPRO Flaw Allow Full System Takeover https://t.co/aoMalov039

    @Dinosn

    18 Feb 2025

    1958 Impressions

    2 Retweets

    5 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 CVE-2025-24865 ⚠️🔴 CRITICAL (10) 🏢 mySCADA - myPRO Manager 🏗️ 0 🔗 https://t.co/Fq7nDbuQXN 🔗 https://t.co/GhDWdZNp23 🔗 https://t.co/ykL4BjjTED #CyberCron #VulnAlert https://t.co/hqFgjBYcQK

    @cybercronai

    17 Feb 2025

    103 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  5. CVE-2025-24865 - mySCADA myPRO Manager - Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary OS commands, upload files, and obtain sensitive information without providing associated credentials. https://t.co/r0mrg2Rjq1

    @gothburz

    14 Feb 2025

    209 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️ Vulnerability Alert: mySCADA myPRO Manager Multiple Vulnerabilities 📅 Timeline: Disclosure: 2025-02-14, Patch: N/A 🆔cveId: CVE-2025-25067, CVE-2025-24865, CVE-2025-22896, CVE-2025-23411 📂affectedVersions: myPRO Manager versions prior to 1.4 🫨Attack Vectors: - OS Command

    @syedaquib77

    14 Feb 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. [CVE-2025-24865: CRITICAL] Unauthenticated access to mySCADA myPRO Manager's web interface poses a severe cyber threat, enabling unauthorized individuals to retrieve sensitive data and upload files.#cybersecurity,#vulnerability https://t.co/dlwPU1H8SE https://t.co/5btVLMxzMB

    @CveFindCom

    13 Feb 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-24865 The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive … https://t.co/CRePPuRIf1

    @CVEnew

    13 Feb 2025

    261 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes