PT-2020-13865 · Sokkia · Sokkia Gnr5 Vanguard

Published

2020-06-15

·

Updated

2020-06-23

·

CVE-2020-14054

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3) SOKKIA GNR5 Vanguard hardware version 212
Description The issue allows remote attackers to bypass admin authentication via a SQL injection attack that uses the User Name or Password field on the "login page" endpoint.
Recommendations For SOKKIA GNR5 Vanguard WEB version 1.2 (build: 91f2b2c3a04d203d79862f87e2440cb7cefc3cd3), consider restricting access to the login page until a patch is available. For SOKKIA GNR5 Vanguard hardware version 212, avoid using the User Name or Password field in the login page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14054

Affected Products

Sokkia Gnr5 Vanguard