Unauthenticated SQL Injection Vulnerability in Edna Reporting Web Service by Texas Instruments
CVE-2020-13505
9.8CRITICAL
What is CVE-2020-13505?
The Edna Reporting web service from Texas Instruments contains a vulnerability allowing unauthenticated SQL injection through the psClass parameter in ednareporting.asmx. Attackers can exploit this flaw by sending specially crafted SOAP web requests, which may lead to unauthorized access and the potential compromise of sensitive data. It is essential for organizations using this service to review their security measures and apply the necessary patches to mitigate the risk of exploitation.
Affected Version(s)
Aveva Aveva eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053