# CVE-2025-24865

## Summary

- **CVE ID:** CVE-2025-24865
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-306
- **Published:** Feb 13, 2025
- **Last Modified:** Mar 12, 2026

## Description

The administrative web interface of 
mySCADA myPRO Manager

can be accessed without authentication 
which could allow an unauthorized attacker to retrieve sensitive 
information and upload files without the associated password.

## Affected Products

- mySCADA — myPRO Manager (0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-16)
- [CNA](https://www.myscada.org/downloads/mySCADAPROManager/)
- [CNA](https://www.myscada.org/contacts/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 7.25%
- **EPSS Percentile:** 94.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._