CVE-2020-13500: SQL Injection
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-13500?
The severity of CVE-2020-13500 is critical.
What is the affected software for CVE-2020-13500?
The affected software for CVE-2020-13500 is Aveva Edna Enterprise Data Historian version 3.0.1.2/7.5.4989.33053.
What is the impact of CVE-2020-13500?
CVE-2020-13500 allows for SQL injections, which can result in data compromise.
How can I fix CVE-2020-13500?
To fix CVE-2020-13500, it is recommended to apply the latest security patches provided by Aveva.
Are there any references for CVE-2020-13500?
Yes, you can find references for CVE-2020-13500 at the following URLs: https://talosintelligence.com/vulnerability_reports/TALOS-2020-1106 and https://us-cert.cisa.gov/ics/advisories/icsa-20-254-01.