Vulnerability Description
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sol-Connect | Sol.Connect Iset-Mpp Meter Firmware | 1.2.4.2 |
| Sol-Connect | Sol.Connect Iset-Mpp Meter | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/540946/100/0/threaded
- http://www.securityfocus.com/bid/100067Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42408/
- http://www.securityfocus.com/archive/1/540946/100/0/threaded
- http://www.securityfocus.com/bid/100067Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/42408/
FAQ
What is CVE-2017-11494?
CVE-2017-11494 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter in a login action.
How severe is CVE-2017-11494?
CVE-2017-11494 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-11494?
Check the references section above for vendor advisories and patch information. Affected products include: Sol-Connect Sol.Connect Iset-Mpp Meter Firmware, Sol-Connect Sol.Connect Iset-Mpp Meter.