A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and authenticate as
Administrator user.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of affected devices is vulnerable to SQL injection when checking authentication data. This could allow an unauthenticated remote attacker to bypass the check and authenticate as Administrator user. | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-05-13T09:38:35.749Z
Updated: 2025-05-13T18:56:33.539Z
Reserved: 2025-02-07T15:33:59.767Z
Link: CVE-2025-26390

Updated: 2025-05-13T18:52:41.606Z

Status : Awaiting Analysis
Published: 2025-05-13T10:15:23.703
Modified: 2025-05-13T19:35:18.080
Link: CVE-2025-26390

No data.