CVE-2024-8950

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Dec 25, 2024
CWE ID 89

Summary

CVE-2024-8950 is a critical SQL Injection vulnerability affecting Arne Informatik's Piramit Automation software. Hackers can exploit this issue by injecting malicious SQL commands, which could result in unauthorized data access or system manipulation. Unlike typical SQL Injection vulnerabilities, this one allows for blind attacks, meaning the attacker doesn't need to see the response to know if their command was successful. Piramit Automation versions before 27.09.2024 are susceptible to this vulnerability. Organizations using this software are advised to apply the forthcoming patch as soon as it becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share