peter bassill · operator
$ cve CVE-2025-24865 JSON

CVE-2025-24865

10.0
CRITICAL · CVSS 3.1 · EPSS 7.2% (pctl 94)

In your normal cycle

Critical by CVSS (10), but no sign of active exploitation.

Description

The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.

Scoring

CVSS10.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS7.25% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2025-02-13
Last modified2026-06-17

Affected (1)

VendorProduct
myscadamypro

References

→ the Explorer  ·  watch your stack  ·  NVD