CVE-2023-1934
48Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 9.8epss 8.1%
de la publicación al arma11 días
Publicada en NVD12 may
1ª PoC+11d
probabilidad de explotación
8.1%top 6% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential infrastructure data, highlighting the severity of this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
SDG Technologies · PnPSCADAPoCs públicas encontradas — 2
exploitdbwww.exploit-db.com/exploits/51448no verificadocve_referencepacketstormsecurity.com/files/172511/PnPSCADA-2.x-SQL-Injection.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.