PT-2020-14637 · Siemens · Desigo Insight

Published

2020-10-15

·

Updated

2022-06-15

·

CVE-2020-15792

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Desigo Insight (All versions)
Description A vulnerability has been identified where the web service does not properly apply input validation for some query parameters in a reserved area. This could allow an authenticated attacker to retrieve data via a content-based blind SQL injection attack.
Recommendations For all versions, consider restricting access to the reserved area of the web service to minimize the risk of exploitation. As a temporary workaround, review and apply proper input validation for query parameters to prevent SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15792

Affected Products

Desigo Insight