CVE-2026-73807
CVSS 9.8 CRITICAL: the mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions.
Vulnerabilità ed exploit · Attacco ad app web
CISA ha pubblicato un advisory su mySCADA myPRO Manager e segnala due vulnerabilità in Version 2.1 e precedenti. Il punto debole non è solo la console web: accesso di rete ai servizi colpiti basta per invocare funzioni privilegiate e per usare il modem GSM collegato come canale SMS.
Una falla lascia aperta l’API di comando a chiamate senza autenticazione; l’altra espone un endpoint HTTP che accetta numero e messaggio e inoltra SMS tramite il modem. In pratica, un attaccante remoto può agire come se avesse privilegi di gestione e può anche far partire messaggi fuori banda attraverso l’impianto.
Il rischio pesa sugli ambienti industriali che usano questo prodotto in manufacturing, energy, transportation, water and wastewater e food and agriculture. Version 2.2 corregge il problema, ma chi ha esposto il sistema in rete deve considerare che il danno non si ferma all’interfaccia: il canale SMS diventa parte della superficie d’attacco.
1 fonte · 15 set
CVSS 9.8 CRITICAL: the mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions.
CVSS 6.3 MEDIUM: the myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem.
CISA Advisories
mySCADA myPRO Manager | CISA
mySCADA myPRO Manager Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.
originalePart of the PlainSec briefing for 2026-09-16
Every edition of this story: mySCADA myPRO Manager espone API e SMS al network