ID

VAR-202105-1707


TITLE

A SQL injection vulnerability exists in the RMP router management platform of Xiamen Sixin Communication Technology Co., Ltd.

Trust: 0.6

sources: CNVD: CNVD-2021-29120

DESCRIPTION

Xiamen Sixin Communication Technology Co., Ltd., a national high-tech enterprise, a leading enterprise of small giants of scientific and technological innovation in Fujian Province, an Internet of Things platform enterprise, an Internet of Things technology expert, an Internet of Things communication equipment and solution provider, specializing in providing smart power and smart cities , Smart water conservancy, smart land disaster, smart fire protection and other industry solutions. The RMP router management platform of Xiamen Sixin Communication Technology Co., Ltd. has a SQL injection vulnerability. Attackers can use the vulnerability to obtain sensitive information in the database.

Trust: 0.6

sources: CNVD: CNVD-2021-29120

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-29120

AFFECTED PRODUCTS

vendor:sixin communicationmodel:rmp router management platform 3.5.0-standardscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-29120

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-29120
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2021-29120
severity: MEDIUM
baseScore: 4.9
vectorString: AV:N/AC:H/AU:S/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-29120

EXTERNAL IDS

db:CNVDid:CNVD-2021-29120

Trust: 0.6

sources: CNVD: CNVD-2021-29120

SOURCES

db:CNVDid:CNVD-2021-29120

LAST UPDATE DATE

2022-05-04T09:21:22.325000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-29120date:2021-04-19T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-29120date:2021-05-20T00:00:00