PT-2025-16253 · Unknown · Sicommnet Basec

Frank Breedijk

+1

·

Published

2025-04-14

·

Updated

2025-04-21

·

CVE-2025-22371

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/AU:Y/V:C
Name of the Vulnerable Software and Affected Versions: SicommNet BASEC (SaaS Service) versions prior to the fixed version, which is not specified.
Description: The issue is related to an SQL Injection vulnerability in the login page of SicommNet BASEC, allowing an unauthenticated remote attacker to bypass authentication and execute arbitrary SQL commands. This vulnerability has been present in the solution at least since December 14, 2021, and likely before that.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-22371

Affected Products

Sicommnet Basec