CVE-2020-10623: SQL Injection
Published Apr 9, 2020
·Updated
Multiple vulnerabilities could allow an attacker with low privileges to perform SQL injection on WebAccess/NMS (versions prior to 3.0.2) to gain access to sensitive information.
Affected Software
1 affected component
Advantech Webaccess\/nms<3.0.2
Event History
Apr 9, 2020
CVE Published
via MITRE·01:03 PM
Data Sourced
via MITRE·01:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-10623?
The severity of CVE-2020-10623 is considered to be moderate, as it allows low-privilege attackers to perform SQL injection.
2
How do I fix CVE-2020-10623?
To fix CVE-2020-10623, update your Advantech WebAccess/NMS software to version 3.0.2 or later.
3
What versions of Advantech WebAccess/NMS are affected by CVE-2020-10623?
Advantech WebAccess/NMS versions prior to 3.0.2 are affected by CVE-2020-10623.
4
What type of attack is associated with CVE-2020-10623?
CVE-2020-10623 is associated with SQL injection attacks that can lead to unauthorized access to sensitive information.
5
Who can exploit CVE-2020-10623?
CVE-2020-10623 can be exploited by attackers with low privileges.