Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-29245

Опубликовано: 19 сент. 2023
Источник: nvd
CVSS3: 8.1
CVSS3: 7.4
EPSS Низкий

Описание

A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets.

Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
Версия от 22.6.0 (включая) до 22.6.3 (исключая)
cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
Версия от 23.0.0 (включая) до 23.1.0 (исключая)
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*
Версия от 22.6.0 (включая) до 22.6.3 (исключая)
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*
Версия от 23.0.0 (включая) до 23.1.0 (исключая)

EPSS

Процентиль: 30%
0.0011
Низкий

8.1 High

CVSS3

7.4 High

CVSS3

Дефекты

CWE-89
CWE-89

Связанные уязвимости

CVSS3: 8.1
github
больше 2 лет назад

A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets. Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, or to alter its structure and data.

EPSS

Процентиль: 30%
0.0011
Низкий

8.1 High

CVSS3

7.4 High

CVSS3

Дефекты

CWE-89
CWE-89