SB2017090104 - Two vulnerabilities in OPW Fuel Management Systems SiteSentinel Integra and SiteSentinel iSite
Published: September 1, 2017
Security Bulletin ID
SB2017090104
CSH Severity
High
Patch available
YES
Number of vulnerabilities
2
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Privilege escalation (CVE-ID: CVE-2017-12733)
The vulnerability allows a remote attacker to gain elevated privileges on the target system.The weakness exists due to improper authentication. A remote attacker can create an application user account to gain administrative privileges.
2) SQL injection (CVE-ID: CVE-2017-12731)
The vulnerability allows a remote attacker to execute arbitrary SQL commands.The vulnerability exists due to a lack of proper validation on user-supplied input within SQL queries. A remote attacker can inject malicious SQL queries, execute SQL commands and gain access to the system.
Remediation
Install update from vendor's website.