PT-2022-8981 · Sevone · Sevone Network Management System

Calvin Phang

·

Published

2022-06-03

·

Updated

2022-06-14

·

CVE-2020-36530

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SevOne Network Management System versions up to 5.7.2.22
Description A critical issue was found in the Alert Summary component, allowing for sql injection through remote manipulation.
Recommendations For SevOne Network Management System versions up to 5.7.2.22, consider restricting access to the Alert Summary component to minimize the risk of exploitation until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36530

Affected Products

Sevone Network Management System