The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.
History

Tue, 01 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Description Multiple SQL injection vulnerabilities in Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, a similar issue to CVE-2012-5861. The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality.
Title Carlo Gavazzi EOS Box SQL Injection
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P'}

cvssV2_0

{'score': 7.8, 'vector': 'AV:N/AC:L/Au:N/C:C/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2012-12-23T21:00:00Z

Updated: 2025-07-01T20:01:06.026Z

Reserved: 2012-12-18T00:00:00Z

Link: CVE-2012-6427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-12-23T21:55:01.547

Modified: 2025-07-01T20:15:24.093

Link: CVE-2012-6427

cve-icon Redhat

No data.