CyberData 011209 SIP Emergency Intercom Blind SQL Injection Vulnerability

Vulnerability

A blind SQL injection vulnerability has been identified in the CyberData 011209 SIP Emergency Intercom, affecting versions prior to 22.0.1. This vulnerability could allow an unauthenticated user to extract sensitive information from the device.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure through SQL injection.

Remediation

Users are advised to update the intercom software to version 22.0.1. For additional guidance, refer to the CISA recommendations for minimizing network exposure of control system devices.

Added: Jun 9, 2025, 11:17 PM
Updated: Jun 9, 2025, 11:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.