CVE-2020-7500 Vulnerability Details

  /     /     /  

CVE-2020-7500 Metadata Quick Info

CVE Published: 16/06/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: schneider | Vendor: n/a | Product: U.motion Servers and Touch Panels (affected versions listed in the security notification)
Status : PUBLISHED

CVE-2020-7500 Description

A CWE-89:Improper Neutralization of Special Elements used in an SQL Command (\'SQL Injection\') vulnerability exists in U.motion Servers and Touch Panels (affected versions listed in the security notification) which could cause arbitrary code to be executed when a malicious command is entered.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-89
CWE Name: CWE-89:Improper Neutralization of Special Elements used in an SQL Command ( SQL Injection )
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).