CVE-2023-22583: SQL Injection in Danfoss AK-EM100
Published Jun 11, 2023
·Updated
The Danfoss AK-EM100 web forms allow for SQL injection in the login forms.
Affected Software
4 affected components
All of the following
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss AK-EM100
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss AK-EM100
Event History
Jun 11, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-22583?
CVE-2023-22583 is a vulnerability in the Danfoss AK-EM100 web forms that allows for SQL injection in the login forms.
2
How severe is CVE-2023-22583?
CVE-2023-22583 has a severity rating of 9.8 (critical).
3
Which software version is affected by CVE-2023-22583?
The Danfoss AK-EM100 firmware versions up to and excluding 2.2.0.12 are affected by CVE-2023-22583.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2023-22583?
The CWE ID for CVE-2023-22583 is CWE-89 (SQL Injection).
5
Are all Danfoss AK-EM100 devices vulnerable to CVE-2023-22583?
No, not all Danfoss AK-EM100 devices are vulnerable to CVE-2023-22583, only those with affected firmware versions.