CSWorks SQL Injection
Published May 20, 2014
7.5
HIGHCVSS 2.0
EPSS 2.50%
Description
SQL injection vulnerability in the LiveData service in CSWorks before 2.5.5233.0 allows remote attackers to execute arbitrary SQL commands via vectors related to pathnames contained in web API requests.
Affected products
-
- Version 0StatusaffectedConstraints<=2.5.5050.0
- Version 2.5.5233.0StatusunaffectedConstraints-
- Version
- ≤ 2.5.5050.0
- 1.0.601.0
- 1.0.612.0
- 1.0.623.0
- 1.0.720.0
- 1.0.801.0
- 1.0.813.0
- 1.0.901.0
- 1.0.3540.0
- 1.0.3560.0
- 1.0.3580.0
- 1.1.3600.0
- 1.1.3674.0
- 1.1.3700.0
- 1.2.3730.0
- 1.2.3800.0
- 1.4.3820.0
- 1.4.3830.0
- 1.4.3850.0
- 1.4.3860.0
- 1.4.3880.0
- 1.4.3900.0
- 1.4.4000.0
- 1.7.4050.0
- 1.7.5000.0
- 2.0.4115.0
- 2.0.4115.1
- 2.1.4386.0
- 2.1.4560.0
- 2.5.4770.0
- 2.5.4770.1
- 2.5.4912.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
CSWorks has addressed this vulnerability in the updated version of CSWorks, Version 2.5.5233.0. The updated version of CSWorks is available at: http://www.controlsystemworks.com/DownloadDescription.aspx .
For additional mitigation and installation information, please review CSWorks’ security release at the following location: http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330
References (5)
- http://ics-cert.us-cert.gov/advisories/ICSA-14-135-01 US Government Resource
- http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330 x_refsource_CONFIRMVendor Advisory
- http://www.securityfocus.com/bid/67427 vdb-entryx_refsource_BID
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-2388 Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-14-135-01
| Link | Providers | Tags |
|---|---|---|
| http://ics-cert.us-cert.gov/advisories/ICSA-14-135-01 | US Government Resource | |
| http://www.controlsystemworks.com/blogengine/post/2014/05/08/Important-CSWorks-security-release-2552330 | x_refsource_CONFIRMVendor Advisory | |
| http://www.securityfocus.com/bid/67427 | vdb-entryx_refsource_BID | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2014-2388 | Advisory | |
| https://www.cisa.gov/news-events/ics-advisories/icsa-14-135-01 |
Change history (0)
No recorded changes yet.