Discover the critical CVE-2021-43987 affecting mySCADA myPRO software. Learn about the hidden administrative account vulnerability and the impact on system security. Find mitigation steps and solutions here.
A critical vulnerability in mySCADA myPRO Versions 8.20.0 and prior allows for the existence of an undocumented administrative account, posing a severe security risk.
Understanding CVE-2021-43987
This CVE involves the presence of a hidden administrative account in mySCADA myPRO software versions, which can lead to unauthorized access and compromised system integrity.
What is CVE-2021-43987?
The vulnerability presents a hidden administrative account that remains inaccessible through the regular web interface, posing a potential security threat as it cannot be deleted or modified through standard procedures.
The Impact of CVE-2021-43987
This vulnerability holds a critical severity level with a base CVSS score of 9.8, highlighting the substantial risk it poses to confidentiality, integrity, and service availability of affected systems.
Technical Details of CVE-2021-43987
This section delves into the specific technical aspects of the CVE to provide a comprehensive understanding.
Vulnerability Description
An additional, nondocumented administrative account exists in mySCADA myPRO Versions 8.20.0 and earlier, which remains hidden from the web interface and is immutable through regular means.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability's low attack complexity enables network-based exploitation without the need for user interaction, making it highly concerning.
Mitigation and Prevention
Taking immediate action and implementing long-term security measures are crucial to address and prevent this vulnerability effectively.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates