Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.
Fixes

Solution

Intrado has provided a patch to mitigate the vulnerability. Any EGWs deployed on older revisions will need to be upgraded to the 5.5/5.6 branch to apply the patch. For assistance in obtaining the patch, contact Intrado's technical support group at 1-888-908-4167 or E911Support@intrado.com https://usdhs-my.sharepoint.com/personal/grayson_gaylor_associates_cisa_dhs_gov1/_layouts/15/E911Support@intrado.com .


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisa-cg

Published:

Updated: 2024-08-01T18:56:22.283Z

Reserved: 2024-02-23T13:46:48.596Z

Link: CVE-2024-1839

cve-icon Vulnrichment

Updated: 2024-08-01T18:56:22.283Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-26T21:15:12.597

Modified: 2024-11-21T08:51:25.720

Link: CVE-2024-1839

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.