The PnPSCADA system, a product of SDG Technologies CC, is...
Vulnerability Description
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively. Consequently, malicious actors could gain access to vital information, such as Industrial Control System (ICS) and OT data, alongside other sensitive records like SMS and SMS Logs. The unauthorized database access exposes compromised systems to potential manipulation or breach of essential infrastructure data, highlighting the severity of this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-1934
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Momen Eldawakhly of Samurai Digital Security Ltd reported this vulnerability to CISA.
References
More from SDG Technologies
View All →Affected Vendor
SDG Technologies
View all reports →