ZeroHour

CVE-2024-47407

niche

Unauthenticated OS Command Injection in mySCADA myPRO Manager

CVSS 4.0
10.0 critical
EPSS
64%p99
Published
()
Modified
AI analysis

mySCADA's myPRO Manager contains an OS command injection flaw (CWE-78): a parameter within a command is not properly validated, allowing an unauthenticated remote attacker to inject arbitrary operating system commands. Because the flaw is network-reachable with no privileges or user interaction required (CVSS 4.0 score 10.0, critical), an attacker who can reach the myPRO Manager interface can send crafted input to the vulnerable parameter and run commands with the service's privileges, with high impact on confidentiality, integrity and availability of the host and the systems it manages. Operators running myPRO Manager, the management component of the myPRO industrial control platform, are affected, typically in OT/SCADA deployments; the available data does not specify affected or fixed version ranges. No public proof-of-concept exists and the CVE is not in CISA KEV, but EPSS assigns a 64% probability of exploitation within 30 days (99th percentile), indicating an elevated near-term exploitation risk.

What to do: Upgrade myPRO Manager to the latest version published by mySCADA, following the vendor/CISA ICS-CERT advisory, since specific fixed versions are not listed in the available data. Until patching is complete, restrict network access to the myPRO Manager interface (firewall/VPN, no direct internet exposure) and monitor for signs of command-injection exploitation given the high EPSS score. Inventory sites running myPRO Manager and confirm the management interface is not reachable from untrusted networks.

Affected
mySCADA myPRO Manager
Estimated exposure
nichelikely on the order of hundreds to low thousands of installations — myPRO Manager is a management component of a small-vendor industrial SCADA/HMI platform typically deployed per industrial site rather than at mass-market scale, and the source data provides no install-base or internet-exposure counts, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.