PT-2024-39185 · Unknown · Shandong Star Measurement/Control Equipment Heating Network Wireless Monitoring System

Wiki

+1

·

Published

2024-09-11

·

Updated

2024-09-12

·

CVE-2024-8705

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System version 5.6.2
Description: A critical issue was found in the system, affecting the GetDataKindByType function of the file /DataSrvs/UCCGSrv.asmx. This issue leads to sql injection and can be exploited remotely. The exploit has been disclosed to the public.
Recommendations: For version 5.6.2, as a temporary workaround, consider disabling the GetDataKindByType function until a patch is available. Restrict access to the /DataSrvs/UCCGSrv.asmx file to minimize the risk of exploitation. Avoid using parameters that may lead to sql injection in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-8705

Affected Products

Shandong Star Measurement/Control Equipment Heating Network Wireless Monitoring System