SQL injection in GENESIS64 and GENESIS32 - CVE-2020-12013

 

SQL injection in GENESIS64 and GENESIS32 - CVE-2020-12013

Published: June 19, 2020 / Updated: July 1, 2020


Vulnerability identifier: #VU29165
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12013
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data within the TestQuery endpoint of the IcoFwxServer service. A remote attacker can use a specially crafted WCF client that interfaces to the FrameWorX Server and execute arbitrary SQL commands within the application database.

Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.


Affected software

GENESIS64
GENESIS32
Energy AnalytiX
BizViz
Hyper Historian
MobileHMI

How to mitigate CVE-2020-12013

Install updates from vendor's website.

GENESIS64 - addressed in versions 10.95.2, 10.95.5, 10.96
GENESIS32 - addressed in versions 9.4, 9.5

External References

Related Security Bulletins