Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

mySCADA PRO Manager Password Disclosure

Medium

Synopsis

A local password is exposed locally. We are working with the vendor for full remediation. Once fully remediated, we will update with technical details.

Solution

A solution has yet to be released.

Disclosure Timeline

February 26, 2025 - Tenable requests disclosure contact from vendor.
March 11, 2025 - Tenable requests disclosure contact from vendor.
March 14, 2025 - mySCADA provides contact information.
March 17, 2025 - Tenable sends disclosure to mySCADA.
March 18, 2025 - mySCADA acknowledges response and indicates they are working on a fix.
April 23, 2025 - Tenable requests status update.
April 24, 2025 - mySCADA responds that a fix will likely be released next week.
May 28, 2025 - Tenable requests fix information as Disclosure Date has come.
May 30, 2025 - mySCADA responds that the issues have been fixed in mySCADA PRO Manager version 1.4.
May 30, 2025- Tenable responds indicating 1.4 seems to have been out for a while and inquires if the second bug we disclosed was fixed in that version or not.
June 3, 2025 - mySCADA responds that the second bug was not fixed.
June 4, 2025 - Tenable inquires as to a timeline for fixing the second bug and notes that the publication date has already passed.
June 5, 2025 - mySCADA responds that they may be able to fix the issue by September.

All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.

Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.

For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.

If you have questions or corrections about this advisory, please email [email protected]

Risk Information

CVE ID: CVE-2025-35941
Tenable Advisory ID: TRA-2025-18
CVSSv3 Base / Temporal Score:
5.5
CVSSv3 Vector:
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products:
mySCADA PRO Manager
Risk Factor:
Medium

Advisory Timeline

2025-06-11 - Initial release.