Impact
This vulnerability allows a logged‑in user to inject arbitrary HQL queries into the NetBotz database via the web‑service interface or web UI. The flaw originates from improper sanitisation of user supplied input in Hibernate, permitting attackers to execute arbitrary database commands. The primary impact is potential data compromise and integrity loss, as attackers could read, modify, or delete records.
Affected Systems
Schneider Electric NetBotz 5 - 750/755 devices. No specific version restrictions are listed, so any installation of this product family potentially contains the flaw.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity. Because the injection requires an authenticated session with the web service or UI, the attack vector is user‑based; attacker must first gain valid credentials. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. Nonetheless, the capacity to execute arbitrary database queries represents a significant risk for confidentiality, integrity, and availability if exploited within a trusted session.
OpenCVE Enrichment