PT-2024-15866 · Group Arge Energy Control Systems · Smartpower

Published

2024-05-27

·

Updated

2024-05-28

·

CVE-2024-0851

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Grup Arge Energy and Control Systems Smartpower versions through V24.05.27
Description The issue is related to an SQL Injection vulnerability due to improper neutralization of special elements used in an SQL command. This allows for SQL Injection attacks.
Recommendations For versions through V24.05.27, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive database operations to minimize the risk of exploitation.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-0851

Affected Products

Smartpower