CISA issued an advisory for mySCADA myPRO Manager 2.1 and earlier, warning that two unauthenticated network-reachable flaws can expose privileged management functions and let an attacker send arbitrary SMS messages through a connected GSM modem. Shirshak Secnora OÜ reported the issues to CISA.
One bug leaves the command API open to remote callers without login, so admin-level actions are reachable directly over the network. The other exposes an HTTP endpoint in the notification gateway that takes a phone number and message and forwards it through the attached modem, so the product can be used as an outbound SMS channel rather than just a dashboard.
For operators in manufacturing, energy, transportation, water and wastewater, and food and agriculture, the exposure sits in the control plane and the modem link it manages. If mySCADA is bridged into operations, a network hit can reach beyond the web UI into messaging or other privileged functions until version 2.2 is in place.
CVSS 6.3 MEDIUM: the myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem.
mySCADA myPRO Manager Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.