CVE-2017-12731

A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The application is vulnerable to injection of malicious SQL queries via the input from the client.
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
opwglobalsitesentinel_isite_atg_firmware
𝑥
≤ 175
opwglobalsitesentinel_isite_atg_firmware
16q3.1:q3.1
opwglobalsitesentinel_integra_500_firmware
𝑥
≤ 175
opwglobalsitesentinel_integra_500_firmware
16q3.1:q3.1
opwglobalsitesentinel_integra_100_firmware
𝑥
≤ 175
opwglobalsitesentinel_integra_100_firmware
16q3.1:q3.1
𝑥
= Vulnerable software versions