Vulnerability Description
Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intrado | 911 Emergency Gateway Firmware | - |
| Intrado | 911 Emergency Gateway | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-163-04Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-163-04Third Party Advisory
FAQ
What is CVE-2024-1839?
CVE-2024-1839 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate da...
How severe is CVE-2024-1839?
CVE-2024-1839 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-1839?
Check the references section above for vendor advisories and patch information. Affected products include: Intrado 911 Emergency Gateway Firmware, Intrado 911 Emergency Gateway.