Impact
The vulnerability is an unauthenticated SQL injection that occurs when the system view fails to neutralize special elements in a SQL SELECT command. An attacker with no special privileges can send crafted input to the system view endpoint and retrieve arbitrary database contents. This results in a total loss of confidentiality, allowing extraction of any data that the system view is permitted to access.
Affected Systems
Affected products include Helmholz myREX24V2, Helmholz myREX24V2.virtual, MB Connect Line mbCONNECT24, and MB Connect Line mymbCONNECT24. The CPE data indicate that version 2.20.0 of the operating system and associated application packages are impacted.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity. The EPSS score is not reported, so the current exploitation probability is unknown, and this vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access to the system view endpoint, exploiting the failure to neutralize input without requiring authentication. An attacker can inject SQL statements over the network to read sensitive database information.
OpenCVE Enrichment