Critical Auth Bypass in mySCADA myPRO Exposes Industrial Control Systems
Two critical vulnerabilities in mySCADA myPRO Manager (v2.1 and earlier) expose industrial control environments to unauthenticated access and SMS abuse via a connected GSM modem — a dangerous combination in operational technology (OT) settings. The root issues reflect failures in both patch management and access control design: privileged management functions were accessible without authentication, and hardware-level interfaces lacked proper input validation. In critical infrastructure environments, such flaws can have physical-world consequences beyond typical IT breaches. The vendor has released a fix in version 2.2, but the window between disclosure and patching represents significant risk for unpatched deployments.
Tactical Insight
Immediate actions
- Upgrade all mySCADA myPRO Manager installations to version 2.2 or later without delay.
- Isolate affected SCADA systems from internet-facing networks until patching is confirmed complete.
- Audit GSM modem configurations and restrict SMS-sending capabilities to authorised processes only.
Long-term improvements
- Implement role-based access control (RBAC) and require authentication for all management interfaces in OT/ICS environments.
- Maintain a comprehensive asset inventory of all industrial control systems and connected hardware peripherals.
- Establish a formal OT-specific vulnerability management programme with defined SLAs for critical patch deployment.
Detection measures
- Deploy network monitoring to alert on unexpected access attempts to SCADA management interfaces.
- Enable logging for all privileged function calls and GSM modem activity, and route logs to a centralised SIEM.
- Conduct regular authenticated and unauthenticated vulnerability scans against OT/ICS assets in a safe, controlled manner.