CVE-2024-43406

HIGH

LF Edge eKuiper < 1.14.2 - SQL Injection via Get Method in sqlKvStore

Title source: llm
STIX 2.1

Description

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. A user could utilize and exploit SQL Injection to allow the execution of malicious SQL query via Get method in sqlKvStore. This vulnerability is fixed in 1.14.2.

Scores

CVSS v3 8.8
EPSS 0.0193
EPSS Percentile 83.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (3)
lf-edge/ekuiper 0 - 1.14.2Go
lfedge/ekuiper < 1.14.2
pypi/ekuiper 0 - 1.14.2PyPI
Published Aug 20, 2024
Tracked Since Feb 18, 2026