mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.emreovunc.com/blog/en/mypro_enum_projectid.rb | not applicable |
https://github.com/EmreOvunc/mySCADA-myPRO-7-projectID-Disclosure | third party advisory exploit |