Impact
AlanWeb SCADA is vulnerable to SQL injection across most scripts and input parameters. Because the application has no protections in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This could lead to unauthorized data disclosure, modification, or deletion, compromising confidentiality, integrity, and availability.
Affected Systems
AlanWeb SCADA is affected, with all releases prior to version 9.8.5 vulnerable. The fix was delivered in AlanWeb SCADA 9.8.5. All installations of earlier versions run at risk regardless of deployment environment.
Risk and Exploitability
The CVSS v3 score of 8.7 indicates high severity; the flaw requires authentication, which limits exposure compared to unauthenticated vulnerabilities but still allows adversaries with valid credentials to fully exploit it. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, yet the high score suggests significant potential impact if an attacker can access the vulnerable inputs.
OpenCVE Enrichment