Impact
The vulnerability is an unauthenticated SQL Injection that occurs within the sync_data24 task because special characters are not properly neutralized in a SQL SELECT statement. An attacker who can reach the sync_data24 service does not need to authenticate, and can supply crafted input that is directly incorporated into the query, allowing the attacker to read arbitrary data from the database. The advisory states that this can lead to a total loss of confidentiality, meaning the attacker can acquire all data that the task has access to.
Affected Systems
Affected products are Helmholz myREX24V2, Helmholz myREX24V2 virtual, MB Connect Line mbCONNECT24, and MB Connect Line mymbCONNECT24. The CPE entries indicate that version 2.20.0 of each product is impacted. No other version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 8.7 reflects high severity. The EPSS score is not available, so the probability of exploitation at the time of this analysis cannot be quantified from the data. The vulnerability is listed as not present in CISA KEV, but the lack of an EPSS entry does not preclude future exploitation. Attack execution requires network access to the sync_data24 endpoint and the ability to inject a payload; authentication is not required, so any system exposed to the network that hosts the task is a potential target.
OpenCVE Enrichment