SQL Injection Vulnerability in eDNA Enterprise Data Historian by ECI
CVE-2020-13500
9.8CRITICAL
What is CVE-2020-13500?
An SQL injection vulnerability exists in the CHaD.asmx web service of eDNA Enterprise Data Historian. This vulnerability allows attackers to exploit the ClassName parameter using specially crafted SOAP web requests. If exploited, it can lead to unauthorized access and manipulation of sensitive data, undermining data integrity and potentially causing significant operational disruptions for the affected systems.
Affected Version(s)
Aveva Aveva eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053