HomeSecurityVulnerabilities expose mySCADA systems to remote compromise

Vulnerabilities expose mySCADA systems to remote compromise

The myPRO product of Czech industrial automation company mySCADA is affected by several critical vulnerabilities, including those that could allow an unauthenticated remote attacker to take complete control of the targeted system.

See also: Microlise confirms ransomware data breach

mySCADA violation myPRO

myPRO is a human-machine interface (HMI) and supervisory control and data acquisition (SCADA) system designed for the visualization and control of industrial processes. The product can run on Windows, macOS and Linux, including servers, PCs and embedded devices.

Cybersecurity researcher Michael Heinzl, who has discovered numerous industrial control system (ICS) vulnerabilities in recent years, discovered that the Manager and Runtime components of mySCADA are affected by five types of flaws.

According to the cybersecurity agency CISA, which coordinated the responsible disclosure of the flaws, and Heinzl, who published his own advisory, the security vulnerabilities include operating system command injection, missing authentication, and path traversal issues.

Heinzl reported his findings to the vendor through CISA in July and August 2024. mySCADA patched the vulnerabilities with the release of myPRO Manager 1.3 and myPRO Runtime 9.2.1.

See also: Protecting digital identity from mass breaches

Four of the five vulnerabilities have been assigned a "critical severity" rating and one has been classified as "high severity."

Vulnerabilities expose mySCADA systems to remote compromise

The flaws could allow an unauthenticated remote attacker to execute arbitrary operating system commands with elevated privileges and gain unauthorized access to the system and files.

Heinzl told SecurityWeek that successful exploitation of the vulnerabilities could allow a remote, unauthenticated attacker to gain administrator control and compromise the affected product, as well as the underlying mySCADA system.

The Censys Internet search engine appears to show several dozen mySCADA HMIs exposed online, but it is unclear if and how many are vulnerable to attacks involving the recently patched flaws.

The researcher noted that the vulnerability to attacks depends on the system configuration. By default, the vulnerable service listens on all network interfaces after installation. CISA noted in its advisory that it is not aware of any attacks that exploit these vulnerabilities in the mySCADA system.

See also: Finastra investigates data breach allegations

Remote hacking involves the unauthorized access and manipulation of computer systems or networks from a location separate from the target device. This technique often exploits flaws in software, networks, or user behavior to gain control or extract sensitive information . Hackers may use a variety of tools and methods, including phishing emails , malware, or exploiting weak passwords, to carry out remote attacks. As cyber threats continue to evolve, organizations and individuals must remain vigilant by implementing strong security measures , keeping software up to date , and educating users on safe computing practices to mitigate the risks associated with remote hacking.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: securityweek

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS