Executive brief
The mySCADA myPRO Manager notification gateway is an industrial control system component used to send SMS messages through a connected GSM modem. The system exposes an unauthenticated HTTP endpoint that allows any network-connected attacker to send arbitrary SMS messages without authentication, potentially disrupting critical facility operations and communications that depend on the SMS service.
Technical details
This is a missing authentication vulnerability (CWE-306) in the HTTP notification gateway endpoint of mySCADA myPRO Manager. The vulnerable endpoint accepts phone number and message parameters from network requests without any authentication checks, allowing an unauthenticated attacker with network access to send SMS messages through the connected GSM modem. The vulnerability requires network access to the notification gateway but no authentication, user interaction, or special preconditions. An attacker can send arbitrary SMS messages to any recipient. Affected versions are mySCADA myPRO Manager 2.1 and earlier; mySCADA Technologies released a fix in version 2.2.
Affected products
- mySCADA Technologies myPRO Manager <=2.1
Timeline
- 2026-09-15: disclosed