ID

VAR-202002-1692


TITLE

SQL Injection Vulnerability in Shijiazhuang Hejia Technology Co., Ltd. Computer Room Dynamic Monitoring System

Trust: 0.6

sources: CNVD: CNVD-2020-04676

DESCRIPTION

The equipment room moving ring monitoring system is a monitoring function of the equipment room's important environment and power equipment, including environmental equipment monitoring (temperature, humidity, smoke, flooding, precision air conditioning, ordinary air conditioning, new fans, etc.), power equipment monitoring (power distribution, Generator, UPS, battery, lightning arrester, etc.), security equipment monitoring (fire protection, access control, video, etc.), etc. There is a SQL injection vulnerability in the Shijiazhuang Hejia Technology Co., Ltd. computer room dynamic ring monitoring system. Attackers can use this vulnerability to obtain sensitive information in the database.

Trust: 0.6

sources: CNVD: CNVD-2020-04676

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2020-04676

AFFECTED PRODUCTS

vendor:shijiazhuang hejiamodel:pems6806 ad-tscope:eqversion:/2.1.8

Trust: 0.6

sources: CNVD: CNVD-2020-04676

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2020-04676
value: HIGH

Trust: 0.6

CNVD: CNVD-2020-04676
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2020-04676

PATCH

title:Dynamic loop monitoring system has SQL injection vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/196563

Trust: 0.6

sources: CNVD: CNVD-2020-04676

EXTERNAL IDS

db:CNVDid:CNVD-2020-04676

Trust: 0.6

sources: CNVD: CNVD-2020-04676

SOURCES

db:CNVDid:CNVD-2020-04676

LAST UPDATE DATE

2022-05-04T10:18:29.073000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2020-04676date:2020-02-12T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2020-04676date:2020-02-21T00:00:00