ID

VAR-202107-1901


TITLE

An SQL injection vulnerability exists in the property integrated billing management cloud platform of Shenzhen China Electric Power Technology Co., Ltd.

Trust: 0.6

sources: CNVD: CNVD-2021-45383

DESCRIPTION

The property integrated billing management system is based on cloud computing, the Internet of Things and advanced smart billing management technology, which realizes the flexible access of power system smart electricity data and other smart terminal data, and supports 4G, RS-485, Ethernet and other communication methods. Enable data interconnection, realize online online recharge, SMS reminder and balance inquiry, etc. Shenzhen China Electric Power Technology Co., Ltd. property integrated billing management cloud platform has SQL injection vulnerabilities. Attackers can use vulnerabilities to obtain sensitive information in the database.

Trust: 0.6

sources: CNVD: CNVD-2021-45383

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-45383

AFFECTED PRODUCTS

vendor:zhongdian powermodel:property integrated billing management cloud platformscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2021-45383

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2021-45383
value: HIGH

Trust: 0.6

CNVD: CNVD-2021-45383
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:C/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2021-45383

EXTERNAL IDS

db:CNVDid:CNVD-2021-45383

Trust: 0.6

sources: CNVD: CNVD-2021-45383

SOURCES

db:CNVDid:CNVD-2021-45383

LAST UPDATE DATE

2022-05-04T09:45:56.203000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-45383date:2021-06-28T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-45383date:2021-07-30T00:00:00