Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-1683 | The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. |
Solution
For v2.9.0.x, please update to version 2.9.0.241231 or later. For v3.0.0.x, please update to version 3.0.0.241231 or later.
Workaround
No workaround given by the vendor.
Thu, 16 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Title | NetVision Information airPASS - SQL injection | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-01-16T15:41:05.904Z
Reserved: 2025-01-14T07:51:47.556Z
Link: CVE-2025-0455
Updated: 2025-01-16T15:41:01.753Z
Status : Received
Published: 2025-01-16T02:15:27.203
Modified: 2025-01-16T02:15:27.203
Link: CVE-2025-0455
No data.
OpenCVE Enrichment
Updated: 2025-06-16T20:37:57Z
EUVD