CVE-2020-13505
Summary
| CVE | CVE-2020-13505 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-24 15:15:00 UTC |
| Updated | 2020-09-25 15:04:00 UTC |
| Description | Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Aveva | Edna Enterprise Data Historian | 3.0.1.2\/7.5.4989.33053 | All | All | All |
| Application | Aveva | Edna Enterprise Data Historian | 3.0.1.2\/7.5.4989.33053 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Talos Website | MISC | talosintelligence.com | Exploit, Technical Description, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.