These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.
History

Tue, 08 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
Description Multiple SQL injection vulnerabilities on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 allow remote attackers to execute arbitrary SQL commands via (1) the inverterselect parameter in a primo action to dettagliinverter.php or (2) the lingua parameter to changelanguagesession.php. These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.
Title Sinapsi eSolar SQL Injection
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P'}

cvssV2_0

{'score': 7.8, 'vector': 'AV:N/AC:L/Au:N/C:C/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2012-11-23T11:00:00

Updated: 2025-07-08T15:23:14.405Z

Reserved: 2012-11-14T00:00:00

Link: CVE-2012-5861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-11-23T12:09:58.367

Modified: 2025-07-08T16:15:25.743

Link: CVE-2012-5861

cve-icon Redhat

No data.