CVE-2017-14851
CRITICALCVSS v3.1: 9.8 · EPSS: 0.0480 (89.7 percentile)
Source data as of:
At a glance
- Severity
- CRITICAL
- CVSS
- 9.8 v3.1 · NVD
- EPSS
- 0.0480 (89.7 percentile) · FIRST.org
- CISA KEV
- No
- Type
- SQL Injection · NVD CWE
- Attack conditions (CVSS vector)
- NetworkNo privilegesNo user interaction · Source: NVD Vector
- Affected vendors
- orpak
- Published
- 2019-06-03 · Modified: 2026-06-02
- References
- Jump to references (3)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Reference http://www.securityfocus.com/bid/108167
- Vendor advisory https://ics-cert.us-cert.gov/advisories/ICSA-19-122-01
- Reference https://www.orpak.com