ID

VAR-202103-1748


TITLE

An SQL injection vulnerability exists in the energy information management system of Chongqing Jutai Internet of Things Group Co., Ltd. (CNVD-2021-10513)

Trust: 0.6

sources: CNVD: CNVD-2021-10513

DESCRIPTION

Chongqing Jutai Internet of Things Group Co., Ltd. is a company engaged in the R&D, production, sales and computer system integration of the software and hardware of Internet of Things products. An SQL injection vulnerability exists in the energy information management system of Chongqing Jutai Internet of Things Group Co., Ltd. Attackers can use vulnerabilities to obtain sensitive information in the database.

Trust: 0.6

sources: CNVD: CNVD-2021-10513

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-10513

AFFECTED PRODUCTS

vendor:chongqing jutai internet of things groupmodel:energy information management systemscope:eqversion:v5.0

Trust: 0.6

sources: CNVD: CNVD-2021-10513

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-10513
value: HIGH

Trust: 0.6

CNVD: CNVD-2021-10513
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-10513

EXTERNAL IDS

db:CNVDid:CNVD-2021-10513

Trust: 0.6

sources: CNVD: CNVD-2021-10513

SOURCES

db:CNVDid:CNVD-2021-10513

LAST UPDATE DATE

2022-05-04T09:59:31.474000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-10513date:2021-02-10T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-10513date:2021-03-07T00:00:00