CVE-2024-50054
📛 CVE Title
mySCADA myPRO Path Traversal
Description
The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- icscert
- CVSS severity
- HIGH
- CVSS score
- 8.7 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N- Effective score
- 8.7 / 10 HIGH source: CNA overview
- CWE(s)
-
CWE-35 - Reserved
- 2024-11-13
- Published
- 2024-11-22 23:22 UTC
- Last updated
- 2024-11-26 17:59 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/50xxx/CVE-2024-50054.json
- Linked Threat
- CVE-2024-50054 — mySCADA myPRO Path Traversal
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-45051 - Assigner
- icscert
- Published
- Nov 22, 2024, 10:22:08 PM
- Updated
- Nov 26, 2024, 4:59:05 PM
- EUVD base score (CVSS 4.0)
-
8.7 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.1600
- Vendors
- mySCADA
- Products
-
myPRO Runtime (0 <9.2.1)myPRO Manager (0 <1.3)
- Aliases
-
GHSA-f6c7-whgm-qp84
ENISA description: The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.
EUVD references (1)
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| mySCADA | myPRO Manager |
0 (affected)
|
— |
| mySCADA | myPRO Runtime |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:patch.com
The best breaking news, stories, and events from the Patch network of local news sites
2026-08-05 15:27 UTC -
web:epatch.pa.gov
Why does PATCH exist? Its purpose is to better enable the public to obtain criminal history record checks. The repository was created and is maintained in accordance with Pennsylvania's Criminal History Information Act contained in Chapter 91 of Title 18, Crimes Code. This Act also directs the Pennsylvania State Police (PSP) to disseminate criminal history data to criminal justice agencies ...
2026-08-05 15:27 UTC -
web:status.n-able.com
If you identify any of these, contact N-able support immediately and engage your own security team. Supported Upgrade Paths Upgrade directly to 2026.3.1 from 2025.4 2026.1 2026.2 2026.3 If you are on an older version, we recommend going to any of the builds above. Then upgrade to this Hotfix version ASAP. If you are unsure of what to do, you can contact support directly. Do I need to update my ...
2026-08-05 15:27 UTC -
web:support.halowaypoint.com
July 29 Patch Overview This update to Halo: Campaign Evolved brings enhanced stability across multiple platforms, adjustments to multiple enemy AI behaviors, and more.
2026-08-05 15:27 UTC -
web:github.com
A script-like system module that patches fs, es, ldr and nifm on boot - impeeza/sys- patch
2026-08-05 15:27 UTC -
web:crimsondesert.pearlabyss.com
Fellow Greymanes, Here are the fixes and improvements that have been added this patch . Major UpdatesThis patch adds various bug fixes and stability improvements. Update ScheduleThe patch is rolling out across all platforms. Please refer to the Update section below to see the state of the patch ...
2026-08-05 15:27 UTC -
web:epatch.pa.gov
Check the status of your Pennsylvania criminal history record through this platform.
2026-08-05 15:27 UTC -
web:na.finalfantasyxiv.com
Patch Notes and Special Sites FINAL FANTASY XIV Hotfixes Promotional Site Patch 7.5 Notes Patch 7.51 Notes Patch 7.55 Notes Promotional Site Patch 7.4 Notes Patch 7.41 Notes Patch 7.45 Notes Promotional Site Patch 7.3 Notes Patch 7.31 Notes Patch 7.35 Notes Patch 7.38 Notes Promotional Site Patch 7.2 Notes Patch 7.21 Notes Patch 7.25 Notes ...
2026-08-05 15:27 UTC -
web:www.rapid7.com
Microsoft is addressing 176 vulnerabilities this September 2025 Patch Tuesday, which is a lot. This includes a zero-day denial of service vulnerability in SQL Server.
2026-05-22 10:39 UTC -
web:blog.qualys.com
EVALUATE Vendor-Suggested Mitigation with Policy Audit With Qualys Policy Audit's Out-of-the-Box Mitigation or Compensatory Controls, reduce the risk of a vulnerability being exploited because the remediation ( fix / patch ) cannot be done now; these security controls are not recommended by any industry standards, such as CIS, DISA-STIG.
2026-05-22 10:39 UTC -
web:www.securityweek.com
Microsoft's August 2025 Patch Tuesday updates address critical vulnerabilities in Windows, Office, and Hyper-V.
2026-05-22 10:39 UTC -
web:blog.talosintelligence.com
Microsoft has released its monthly security update for August 2025, which includes 111 vulnerabilities affecting a range of products, including 13 that Microsoft marked as "critical".
2026-05-22 10:39 UTC -
web:cyberpress.org
Cybersecurity researchers at Cymulate have discovered a critical vulnerability that bypasses Microsoft's recent security patch , allowing attackers to extract NTLM credential hashes without any user interaction. The new vulnerability, assigned CVE -2025-50154, demonstrates that Microsoft's fix for the original CVE -2025-24054 was incomplete, leaving systems vulnerable to zero-click attacks ...
2026-05-22 10:39 UTC -
web:isc.sans.edu
Macs are affected as well, but a patch is currently only available for Windows. CVE -2025-49719: This vulnerability has already been made public. It does allow for information disclosure on a Microsoft SQL Server. To patch , you must patch the OLE DB Driver. CVE -2025-49717: Exploitation is considered less likely for this vulnerability.
2026-05-22 10:39 UTC -
web:krebsonsecurity.com
Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited ...
2026-05-22 10:39 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 10:39 UTC -
web:www.computerworld.com
Each month, the team at Readiness analyzes the latest Patch Tuesday updates from Microsoft and provides detailed, actionable testing guidance. The company's Patch Tuesday release for February ...
2026-05-22 10:39 UTC -
web:www.ninjaone.com
Overview KB5087054 is a cumulative security and reliability update for the .NET Framework targeting Windows 11 version 24H2 systems. Released on May 12, 2026, this patch addresses critical vulnerabilities affecting both .NET Framework 3.5 and 4.8.1 installations. The update is designed to be deployed as part of standard maintenance routines and is available through multiple distribution ...
2026-05-22 10:39 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-50054.json.
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:myscada:mypro_manager:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mypro_manager",
"vendor": "myscada",
"versions": [
{
"lessThan": "1.3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:a:myscada:mypro_runtime:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mypro_runtime",
"vendor": "myscada",
"versions": [
{
"lessThan": "9.2.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-50054",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-26T16:58:05.074931Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T16:59:05.931Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "myPRO Manager",
"vendor": "mySCADA",
"versions": [
{
"lessThan": "1.3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unaffected",
"product": "myPRO Runtime",
"vendor": "mySCADA",
"versions": [
{
"lessThan": "9.2.1",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Michael Heinzl reported these vulnerabilities to CISA."
}
],
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<span style=\"background-color: rgb(255, 255, 255);\">\n\n<span style=\"background-color: rgb(255, 255, 255);\">The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system.</span>\n\n</span>"
}
],
"value": "The back-end does not sufficiently verify the user-controlled filename parameter which makes it possible for an attacker to perform a path traversal attack and retrieve arbitrary files from the file system."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.7,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "NONE",
"vulnIntegrityImpact": "NONE",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-35",
"description": "CWE-35",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-22T22:22:08.207Z",
"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"shortName": "icscert"
},
"references": [
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-326-07"
}
],
"solutions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "<p>mySCADA recommends updating to the latest versions:</p><ul><li>mySCADA PRO Manager <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.myscada.org/resources/\">1.3</a></li><li>mySCADA PRO Runtime <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.myscada.org/resources/\">9.2.1</a></li></ul>\n\n<br>"
}
],
"value": "mySCADA recommends updating to the latest versions:\n\n * mySCADA PRO Manager 1.3 https://www.myscada.org/resources/ \n * mySCADA PRO Runtime 9.2.1 https://www.myscada.org/resources/"
}
],
"source": {
"advisory": "ICSA-24-326-07",
"discovery": "EXTERNAL"
},
"title": "mySCADA myPRO Path Traversal",
"x_generator": {
"engine": "Vulnogram 0.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
"assignerShortName": "icscert",
"cveId": "CVE-2024-50054",
"datePublished": "2024-11-22T22:22:08.207Z",
"dateReserved": "2024-11-13T20:44:28.734Z",
"dateUpdated": "2024-11-26T16:59:05.931Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}