Siemens OZW672
cpe:2.3:h:siemens:ozw672:*:*:*:*:*:*:*, +1 more
- < V6.0
A SQL injection vulnerability has been identified in the web services of Siemens OZW672 and OZW772 devices, all versions prior to V6.0. This vulnerability allows an unauthenticated remote attacker to manipulate authentication checks and gain access as an Administrator user.
Exploitation of this vulnerability allows an unauthenticated remote attacker to bypass authentication checks and authenticate as an Administrator user on the affected device.
Siemens has released new versions for the affected products. Users are advised to update to the latest versions. Product-specific update instructions can be found on the Siemens Support website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.