ID

VAR-201608-0491


TITLE

CIMCO DSS-MAX Decision Support System Has SQL Injection Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2016-04060

DESCRIPTION

CIMCO is the DNC system with the largest installed capacity in the world. It is mainly used for network communication and machine tool monitoring of CNC machine tools. CIMCO DSS-Max Server is DNC / MDC decision support service software, through which the DNC / MDC database can be easily managed. The CIMCO DSS-MAX decision support system has a SQL injection vulnerability. Because the DSS-Max system information query page is not strictly filtered, it allows attackers to launch SQL injection attacks using GET requests.

Trust: 0.6

sources: CNVD: CNVD-2016-04060

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2016-04060

AFFECTED PRODUCTS

vendor:cimcomodel:dss-maxscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2016-04060

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2016-04060
value: HIGH

Trust: 0.6

CNVD: CNVD-2016-04060
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2016-04060

EXTERNAL IDS

db:CNVDid:CNVD-2016-04060

Trust: 0.6

sources: CNVD: CNVD-2016-04060

SOURCES

db:CNVDid:CNVD-2016-04060

LAST UPDATE DATE

2022-05-04T09:39:46.993000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2016-04060date:2016-12-13T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2016-04060date:2016-08-01T00:00:00