SQL Injection Vulnerability in Advantech WebAccess Node
CVE-2020-12014
7.5HIGH
Summary
The Advantech WebAccess Node prior to version 9.0.0, along with version 8.4.4 and earlier, is susceptible to SQL injection due to improper input sanitation. This vulnerability allows attackers to inject malicious SQL commands, potentially compromising the integrity and confidentiality of data stored in the database.
Affected Version(s)
Advantech WebAccess Node WebAccess Node Version 8.4.4 and prior, WebAccess Node Version 9.0.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved