B
今週中
mySCADA myPRO Managerのバージョン2.1以前に、認証および認可の不備による深刻な脆弱性
📌 一言でいうと
mySCADA myPRO Managerのバージョン2.1以前に、認証および認可の不備による深刻な脆弱性が確認されました。攻撃者は特権管理機能へのアクセスや、接続されたGSMモデムを介した任意のSMS送信が可能です。CVSS v3スコアは9.8と非常に高く、迅速な対応が推奨されます。
🔍該当判定
- mySCADA社の管理ソフト「myPRO Manager」を導入している
- myPRO Managerのバージョンが 2.1 以前である
- myPRO Managerをネットワークに接続し、外部からアクセス可能な状態にしている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるバージョンのmySCADA myPRO Managerを使用している場合は、ベンダーが提供する最新のアップデートを適用し、APIへのネットワークアクセス制限を検討してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】mySCADA myPRO Manager 脆弱性 (CVE-2026-73807, CVE-2026-82567) 対応について
お疲れさまです。mySCADA myPRO Managerに関する脆弱性情報共有です。
■ 概要
mySCADA myPRO ManagerのコマンドAPIにおいて、特権機能に対する認証・認可の不備が判明しました。未認証の攻撃者がネットワーク経由で特権管理機能へのアクセスや、GSMモデムを利用した任意のSMS送信を行う可能性があります。CVSS v3スコアは9.8 (Critical) です。
■ 影響範囲
- 対象製品: mySCADA myPRO Manager
- 対象バージョン: 2.1 以前
■ 対応手順
1. 利用中のmySCADA myPRO Managerのバージョンを確認してください。
2. ベンダーより提供される最新の修正パッチを適用してください。
3. 暫定対応として、APIへのアクセスを信頼できるネットワークに制限することを検討してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-258-03
対応優先度: 高
対応期限: 速やかに
お疲れさまです。mySCADA myPRO Managerに関する脆弱性情報共有です。
■ 概要
mySCADA myPRO ManagerのコマンドAPIにおいて、特権機能に対する認証・認可の不備が判明しました。未認証の攻撃者がネットワーク経由で特権管理機能へのアクセスや、GSMモデムを利用した任意のSMS送信を行う可能性があります。CVSS v3スコアは9.8 (Critical) です。
■ 影響範囲
- 対象製品: mySCADA myPRO Manager
- 対象バージョン: 2.1 以前
■ 対応手順
1. 利用中のmySCADA myPRO Managerのバージョンを確認してください。
2. ベンダーより提供される最新の修正パッチを適用してください。
3. 暫定対応として、APIへのアクセスを信頼できるネットワークに制限することを検討してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-258-03
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] mySCADA myPRO Manager Vulnerabilities (CVE-2026-73807, CVE-2026-82567)
Dear Team,
We are sharing critical vulnerability information regarding mySCADA myPRO Manager.
■ Overview
Missing authentication and authorization vulnerabilities have been discovered in the command API of mySCADA myPRO Manager. An unauthenticated attacker with network access could exploit these to access privileged management functions or send arbitrary SMS messages via the connected GSM modem. The CVSS v3 score is 9.8 (Critical).
■ Affected Scope
- Product: mySCADA myPRO Manager
- Versions: 2.1 and earlier
■ Mitigation Steps
1. Verify the version of mySCADA myPRO Manager currently in use.
2. Apply the latest security updates provided by the vendor.
3. As a temporary measure, restrict network access to the API to trusted sources only.
■ Reference
- CISA ICS Advisory ICSA-26-258-03
Priority: High
Deadline: Immediate
Dear Team,
We are sharing critical vulnerability information regarding mySCADA myPRO Manager.
■ Overview
Missing authentication and authorization vulnerabilities have been discovered in the command API of mySCADA myPRO Manager. An unauthenticated attacker with network access could exploit these to access privileged management functions or send arbitrary SMS messages via the connected GSM modem. The CVSS v3 score is 9.8 (Critical).
■ Affected Scope
- Product: mySCADA myPRO Manager
- Versions: 2.1 and earlier
■ Mitigation Steps
1. Verify the version of mySCADA myPRO Manager currently in use.
2. Apply the latest security updates provided by the vendor.
3. As a temporary measure, restrict network access to the API to trusted sources only.
■ Reference
- CISA ICS Advisory ICSA-26-258-03
Priority: High
Deadline: Immediate