CVE-2012-6427 - CVE House
Back to Database
Status published High CVE-2012-6427

Carlo Gavazzi EOS Box SQL Injection

Vulnerability Description

The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6427

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Carlo Gavazzi Automation

View all reports →

Affected Software

EOS-Box
Vulnerable Versions:
0

Timeline

Official Publish: December 23rd, 2012
Last Modified: July 1st, 2025
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)