CVE-2025-24865: critical vulnerability in mySCADA myPRO Manager
mySCADA myPRO Manager Missing Authentication for Critical Function
Published · Updated
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 10epss 7.2%
from disclosure to weapon0 days
Published on NVDFeb 13
metasploitFeb 13
exploitation probability
7.2%top 6% of all CVEs
observed exploitation
nono source reports it
The administrative web interface of
mySCADA myPRO Manager
can be accessed without authentication
which could allow an unauthorized attacker to retrieve sensitive
information and upload files without the associated password.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
mySCADA · myPRO ManagerRelated CVEs — mySCADA myPRO Manager
In the same product, most dangerous first.
CVE-2024-47407CRITICALmySCADA myPRO OS Command InjectionEPSS 63.8%CVE-2025-22896CRITICALmySCADA myPRO Manager Cleartext Storage of Sensitive InformationEPSS 3.6%CVE-2024-52034CRITICALmySCADA myPRO OS Command InjectionEPSS 1.7%CVE-2025-25067CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.7%CVE-2025-20061CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.3%CVE-2025-20014CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.3%