Skip to content
COOEY

EXPOSURES › CVE-2020-24841

CVE-2020-24841

CRITICAL
DETAIL
SourceNVD · cve Published2021-02-16 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24841 ↗
SHAME 35/100

PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Damning security failure with SQL injection in critical PNPSCADA version
cooey ↗ severe-fallout -0.90
Critical vulnerability disclosed
"PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database."
www.usatoday.com ↗ severe-fallout +0.00
Irrelevant to SDG vendor
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
NVD ↗ severe-fallout +0.00
Irrelevant CVE ID
www.databreachtoday.com ↗ severe-fallout +0.00
Irrelevant Tenda router topic
CISA ↗ severe-fallout +0.00
Generic ICS advisory page
www.hud.gov ↗ severe-fallout +0.00
Irrelevant HUD funding list
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.