CVE-2012-6427
Carlo Gavazzi EOS-Box < 1.0.0.1080_2.1.10 - Unauthenticated SQL Injection
Title source: llmDescription
The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.
References (2)
Core 2
Core References
US Government Resource
http://www.us-cert.gov/control_systems/pdf/ICSA-12-354-02.pdf
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-12-354-02
Scores
EPSS
0.0121
EPSS Percentile
65.2%
Details
CWE
CWE-89
Status
published
Products (3)
Carlo Gavazzi Automation/EOS-Box
< 1.0.0.1080_2.1.10
carlosgavazzi/eos-box_photovoltaic_monitoring_system
carlosgavazzi/eos-box_photovoltaic_monitoring_system_firmware
< 1.0.0
Published
Dec 23, 2012
Tracked Since
Feb 18, 2026