Impact
The vulnerability is a mass assignment flaw in Sustainable Irrigation Platform (SIP) version 5.2.16 that allows unauthenticated attackers to overwrite key configuration values by including arbitrary parameter names in HTTP requests. Attackers can change sensitive settings such as the passphrase and the listening port. Changing the passphrase undermines authentication, while altering the port can disrupt communication or redirect traffic, thus compromising the system’s integrity and availability. The flaw corresponds to CWE‑915 and enables a malicious actor to alter system behavior without valid credentials.
Affected Systems
Dan‑in‑CA’s Sustainable Irrigation Platform 5.2.16 is affected. No other versions are listed in the available CNA data.
Risk and Exploitability
The CVSS score of 8.8 marks this as a high‑severity vulnerability, yet the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild at present. The flaw is not listed in the CISA KEV catalog. Because the attack vector exploits HTTP parameters it can be triggered from any network location with access to the SIP instance. The absence of request validation also opens a cross‑site request forgery attack path, broadening the potential impact. Overall, the risk is moderate until a patch is applied, but the high severity warrants prompt remediation.
OpenCVE Enrichment