mySCADA myPRO Manager
A critical vulnerability in mySCADA myPRO Manager versions 2.1 and below allows unauthenticated attackers to access privileged management functions and send arbitrary SMS messages through a connected GSM modem. This affects critical infrastructure sectors globally, including manufacturing, energy, and transportation. MySCADA Technologies has released version 2.2 to address the issue, and users are strongly advised to update immediately.
A critical vulnerability has been identified in mySCADA myPRO Manager, specifically versions 2.1 and earlier. The myPRO Manager command API lacks proper authentication for privileged functions, creating an opening for unauthenticated attackers with network access to exploit this weakness. This allows them to gain access to privileged management functions and, more concerningly, send arbitrary SMS messages through a connected GSM modem. The vulnerability is impacting a wide range of industries, including critical infrastructure sectors such as manufacturing, energy, food and agriculture, and transportation systems, worldwide. MySCADA Technologies has released version 2.2 to address these issues and recommends that users update to the latest version. Users will be notified within mySCADA Pro Manager if a new version is available, or they can download it from the provided webpage: https://www.myscada.org/downloads/mySCADAPROManager/. The vulnerability is linked to CWE-306 (Missing Authentication for Critical Function) and CWE-862 (Missing Authorization). CISA recommends minimizing network exposure for control system devices, isolating them behind firewalls, and utilizing secure remote access methods like VPNs – recognizing that VPNs themselves can have vulnerabilities. Organizations are encouraged to perform impact analysis and risk assessments and to implement recommended cybersecurity strategies for proactive defense of ICS assets. CISA also advises users to be vigilant against social engineering attacks and to report any suspected malicious activity.