Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

Project Subscriptions

Vendors Products
Riello-ups Subscribe
Netman 204 Subscribe
Netman 204 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 17:30:00 +0000

Type Values Removed Values Added
References

Mon, 30 Sep 2024 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Riello-ups netman 204
CPEs cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*
Vendors & Products Riello-ups netman 204
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 27 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Riello-ups netman 204 Firmware
CPEs cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:* cpe:2.3:o:riello-ups:netman_204_firmware:*:*:*:*:*:*:*:*
Vendors & Products Riello-ups netman 204
Riello-ups netman 204 Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Riello-ups
Riello-ups netman 204
CPEs cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*
Vendors & Products Riello-ups
Riello-ups netman 204
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.
Title SQL Injection
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CyberDanube

Published:

Updated: 2025-11-04T16:16:07.925Z

Reserved: 2024-09-15T08:33:34.357Z

Link: CVE-2024-8877

cve-icon Vulnrichment

Updated: 2025-11-04T16:16:07.925Z

cve-icon NVD

Status : Modified

Published: 2024-09-25T01:15:47.267

Modified: 2025-11-04T17:16:18.057

Link: CVE-2024-8877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses