A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.
History

Fri, 06 Dec 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens syngo Plaza Vb30e
CPEs cpe:2.3:a:siemens:syngo_plaza_vb30e:*:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens syngo Plaza Vb30e
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 13:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF05). The affected application do not properly sanitize input data before sending it to the SQL server. This could allow an attacker with access to the application could use this vulnerability to execute malicious SQL commands to compromise the whole database.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-12-06T13:14:16.935Z

Updated: 2024-12-06T17:58:49.178Z

Reserved: 2024-11-08T12:49:09.651Z

Link: CVE-2024-52335

cve-icon Vulnrichment

Updated: 2024-12-06T17:58:38.647Z

cve-icon NVD

Status : Received

Published: 2024-12-06T14:15:21.230

Modified: 2024-12-06T14:15:21.230

Link: CVE-2024-52335

cve-icon Redhat

No data.