7.5
CVSSv2

CVE-2017-11494

Published: 02/08/2017 Updated: 09/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and previous versions allows remote malicious users to execute arbitrary SQL commands via the user parameter in a login action.

Vulnerable Product Search on Vulmon Subscribe to Product

sol-connect sol.connect_iset-mpp_meter_firmware 1.2.4.2

Exploits

Vulnerability type: SQL injection, leading to administrative access through authentication bypass ----------------------------------- Product: SOLConnect ISET-mpp meter ----------------------------------- Affected version: SOLConnect ISET-mpp meter 1242 and possibly earlier Vulnerable parameter: user ------------------------ Credit: Andy T ...
SOLConnect ISET-mpp meter version 1242 suffers from a remote SQL injection vulnerability that allows for authentication bypass ...