CVE Intelligence
Skip to main content
MEDIUM

CVE-2024-11025

CVE-2024-11025 — SMA: SQL injection in Sunny Central UP

An authenticated attacker with low privileges may use a SQL Injection vulnerability in the affected products administration panel to gain read and write access to a specific log file of the device.

Published Updated Sources: cvelistV5, CERTVDE

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

0%

chance of exploitation in 30 days

Affects

sma

56 products listed

CVSS base

5.4

MEDIUM

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

None

none · proof-of-concept · active

Automatable

No

can an attacker script all four kill-chain steps

Technical impact

Partial

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (1)

Products (56)

sunny central sc 1760 ussunny central sc 1850 ussunny central sc 2000 ev ussunny central sc 2000 ussunny central sc 2200 10sunny central sc 2200 ussunny central sc 2475 10sunny central sc 2500 ev ussunny central sc 2660 upsunny central sc 2660 up ussunny central sc 2750 ev ussunny central sc 2750 up ussunny central sc 2800 upsunny central sc 2800 up ussunny central sc 2930 upsunny central sc 2930 up ussunny central sc 3060 upsunny central sc 3060 up ussunny central sc 4000 upsunny central sc 4000 up ussunny central sc 4200 upsunny central sc 4200 up ussunny central sc 4400 upsunny central sc 4400 up jpsunny central sc 4400 up ussunny central sc 4600 upsunny central sc 4600 up ussunny central storage scs 1900 10sunny central storage scs 2200 10sunny central storage scs 2300 up xtsunny central storage scs 2300 up xt ussunny central storage scs 2400 up xtsunny central storage scs 2400 up xt ussunny central storage scs 2475 10sunny central storage scs 2530 up xtsunny central storage scs 2530 up xt ussunny central storage scs 2630 up xtsunny central storage scs 2630 up xt ussunny central storage scs 2900 10sunny central storage scs 3450 upsunny central storage scs 3450 up ussunny central storage scs 3450 up xtsunny central storage scs 3450 up xt jpsunny central storage scs 3450 up xt ussunny central storage scs 3600 upsunny central storage scs 3600 up ussunny central storage scs 3600 up xtsunny central storage scs 3600 up xt ussunny central storage scs 3800 upsunny central storage scs 3800 up ussunny central storage scs 3800 up xtsunny central storage scs 3800 up xt ussunny central storage scs 3950 upsunny central storage scs 3950 up ussunny central storage scs 3950 up xtsunny central storage scs 3950 up xt us

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
5.4CVSS 3.1MEDIUMcvelistV5

Weakness & attack patterns

  • CWE-89

References

1 on the record

Elsewhere on this site

  • smaevery CVE for this vendor
  • CWE-89other pages naming this weakness

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.