Record summary

CVE-2024-8877 has a selected CVSS score of 6.9 (medium); EIP currently links 1 Nuclei template.

Description

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Oct 15, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 27, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListThrough 4.05affected

Default status: unknown

CVE List, VulnCheckThrough 4.05affected

Nuclei templates

1
ProjectDiscoveryCRITICALRiello Netman 204 - SQL InjectionCVSS 9.8

The three endpoints /cgi-bin/db_datalog_w.cgi, /cgi-bin/db_eventlog_w.cgi, and /cgi-bin/db_multimetr_w.cgi are vulnerable to SQL injection without prior authentication. This enables an attacker to modify the collected log data in an arbitrary way.

Impact

Unauthenticated attackers can exploit SQL injection to modify collected log data, extract sensitive information, and potentially gain complete control of the Netman 204 device through multiple vulnerable CGI endpoints.

Remediation

Apply security patches from Riello for Netman 204 firmware to address the SQL injection vulnerabilities in db_datalog_w.cgi, db_eventlog_w.cgi, and db_multimetr_w.cgi endpoints.

WeaknessesCWE-89
Authorss4e-io
Template tagscvecve2024netmansqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
Shodan: title:"netman 204"
FOFA: title="netman 204"
Google: intitle:"netman 204"

Source: ProjectDiscovery

References

3