SQL Injection Vulnerability in R-SeeNet Product by Cisa
CVE-2020-25157
7.5HIGH
Summary
The R-SeeNet product versions 1.5.1 through 2.4.10 are susceptible to SQL injection attacks. This vulnerability enables remote attackers to manipulate database queries, which can lead to unauthorized access and retrieval of sensitive information from the affected database systems. Promptly patching these versions is essential to mitigate potential exploitation risks.
Affected Version(s)
Advantech R-SeeNet Versions 1.5.1 through 2.4.10
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved