PT-2022-6831 · Ce805M · Ce805M

Published

2022-12-13

·

Updated

2022-12-13

CVSS v2.0

8.5

High

AV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions CE805M (affected versions not specified)
Description The issue is related to the CMD W REG command handler of the CE805M data collection and transmission device, specifically with the CEAR MWDI DFLT PASSWORD register. It is associated with a lack of protection measures for the SQL query structure. Exploitation of this issue could allow a remote attacker to compromise the integrity of the database or cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2023-04842

Affected Products

Ce805M