vendor:
rConfig
by:
azhen
8.8
CVSS
HIGH
SQL Injection
89
CWE
Product Name: rConfig
Affected Version From: <= v3.9.7
Affected Version To: <= v3.9.7
Patch Exists: YES
Related CWE: CVE-2022-45030
CPE: a:rconfig:rconfig
Platforms Tested: Linux
2022
rconfig 3.9.7 – Sql Injection (Authenticated)
rConfig is a web-based network device configuration management application. A SQL injection vulnerability exists in rConfig 3.9.7 and prior versions. An authenticated attacker can exploit this vulnerability to execute arbitrary SQL commands on the underlying database. This can be exploited to gain access to sensitive information such as usernames and passwords.
Mitigation:
Upgrade to the latest version of rConfig, which is not vulnerable to this attack.