Lucene search

K
cveCyberDanubeCVE-2024-8877
HistorySep 25, 2024 - 1:15 a.m.

CVE-2024-8877

2024-09-2501:15:47
CWE-89
CyberDanube
web.nvd.nist.gov
31
cve-2024-8877
sql injection
riello netman 204
sqlite database
netman 204

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

39.6%

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

Affected configurations

Nvd
Node
riello-upsnetman_204_firmwareRange4.05
AND
riello-upsnetman_204Match-
VendorProductVersionCPE
riello-upsnetman_204_firmware*cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
riello-upsnetman_204-cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Netman 204",
    "vendor": "Riello",
    "versions": [
      {
        "lessThanOrEqual": "4.05",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS4

6.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/SC:N/VI:L/SI:N/VA:N/SA:N

AI Score

7.6

Confidence

Low

EPSS

0.001

Percentile

39.6%