CVE-2024-8877
SQL Injection
Record summary
CVE-2024-8877 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.
Description
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 15, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 27, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Netman 204Browse Riello / Netman 204Default status: unaffected | CVE List | Through 4.05 | affected |
netman_204_firmwareBrowse riello-ups / netman_204_firmwareDefault status: unknown | CVE List, VulnCheck | Through 4.05 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALRiello Netman 204 - SQL InjectionCVSS 9.8
The three endpoints /cgi-bin/db_datalog_w.cgi, /cgi-bin/db_eventlog_w.cgi, and /cgi-bin/db_multimetr_w.cgi are vulnerable to SQL injection without prior authentication. This enables an attacker to modify the collected log data in an arbitrary way.
Impact
Unauthenticated attackers can exploit SQL injection to modify collected log data, extract sensitive information, and potentially gain complete control of the Netman 204 device through multiple vulnerable CGI endpoints.
Remediation
Apply security patches from Riello for Netman 204 firmware to address the SQL injection vulnerabilities in db_datalog_w.cgi, db_eventlog_w.cgi, and db_multimetr_w.cgi endpoints.
Source: ProjectDiscovery