Unauthenticated SQL Injection Vulnerability in Edna Reporting Web Service by Texas Instruments
CVE-2020-13505

9.8CRITICAL

Key Information:

Vendor

Aveva

Status
Vendor
CVE Published:
24 September 2020

What is CVE-2020-13505?

The Edna Reporting web service from Texas Instruments contains a vulnerability allowing unauthenticated SQL injection through the psClass parameter in ednareporting.asmx. Attackers can exploit this flaw by sending specially crafted SOAP web requests, which may lead to unauthorized access and the potential compromise of sensitive data. It is essential for organizations using this service to review their security measures and apply the necessary patches to mitigate the risk of exploitation.

Affected Version(s)

Aveva Aveva eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.