PatchSiren cyber security CVE debrief
CVE-2025-23411 mySCADA CVE debrief
CVE-2025-23411 affects mySCADA myPRO Manager versions before 1.4. CISA’s advisory describes a cross-site request forgery (CSRF) issue that could allow an attacker to obtain sensitive information after tricking a victim into visiting an attacker-controlled website. The provided data lists the issue as MEDIUM severity (CVSS 6.3) and shows no CISA KEV entry.
- Vendor
- mySCADA
- Product
- myPRO Manager
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-13
- Original CVE updated
- 2025-02-13
- Advisory published
- 2025-02-13
- Advisory updated
- 2025-02-13
Who should care
Organizations running mySCADA myPRO Manager, especially OT/ICS operators, system administrators, and security teams responsible for managing the product and its access controls.
Technical summary
The affected product is vulnerable to CSRF. The attack requires user interaction: an attacker must get a victim to visit an attacker-controlled website. CISA’s supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L, reflecting a network-reachable issue that can affect confidentiality, integrity, and availability at low impact levels.
Defensive priority
Medium priority. Apply the vendor fix promptly if the product is in use, because the issue is publicly disclosed and a patched version is available.
Recommended defensive actions
- Update mySCADA myPRO Manager to version 1.4 or later.
- Confirm which systems run mySCADA myPRO Manager and check whether any instances are still below 1.4.
- Follow CISA ICS recommended practices and best practices for defense in depth around management interfaces and operator workstations.
- Review user awareness and browsing behavior for accounts that can access the product, since the attack path depends on a victim visiting a malicious website.
- Use the CISA advisory and official CVE/NVD records to validate remediation status in your environment.
Evidence notes
Source corpus shows CISA CSAF advisory ICSA-25-044-16 for CVE-2025-23411, with affected product listed as 'mySCADA myPRO Manager: <1.4' and remediation to update to v1.4. The description in the advisory states the flaw is CSRF that could expose sensitive information and requires the victim to visit an attacker-controlled website. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-23411 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-23411
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-23411 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-23411
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-044-16.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-16
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.