Vulnerability Description
The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Advantech | R-Seenet | >= 1.5.1, <= 2.4.10 |
Related Weaknesses (CWE)
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-289-02Third Party AdvisoryUS Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-289-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-25157?
CVE-2020-25157 is a vulnerability with a CVSS score of 7.5 (HIGH). The R-SeeNet webpage (1.5.1 through 2.4.10) suffers from SQL injection, which allows a remote attacker to invoke queries on the database and retrieve sensitive information.
How severe is CVE-2020-25157?
CVE-2020-25157 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-25157?
Check the references section above for vendor advisories and patch information. Affected products include: Advantech R-Seenet.