PT-2024-38064 · Semtek · Sempos

Pınar Taşğin

·

Published

2024-09-04

·

Updated

2024-09-05

·

CVE-2024-7078

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Semtek Sempos versions through 31072024
Description The issue is related to an Improper Neutralization of Special Elements used in an SQL Command, also known as a SQL Injection vulnerability. This allows unauthorized database access.
Recommendations Update to version 31072024 to patch the issue. As a temporary workaround, consider restricting access to the database to minimize the risk of exploitation. Avoid using user-input data in SQL commands until the issue is resolved.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-7078

Affected Products

Sempos