VYPR
Unrated severityNVD Advisory· Published Sep 5, 2023· Updated Jan 16, 2025

ARDEREG Sistemas SCADA SQL Injection

CVE-2023-4485

Description

ARDEREG ​Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the database. In this case, the vulnerability could allow an attacker to execute arbitrary SQL queries through the login page, potentially leading to unauthorized access, data leakage, or even disruption of critical industrial processes.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Unauthenticated blind SQL injection in ARDEREG Sistema SCADA Central login page (versions 2.203 and prior) allows remote attackers to execute arbitrary SQL queries.

Vulnerability

The vulnerability is an unauthenticated blind SQL injection in the login page of ARDEREG Sistema SCADA Central versions 2.203 and prior. [1] The login page fails to properly neutralize special elements used in SQL commands, allowing an attacker to manipulate SQL query logic. [1]

Exploitation

An attacker can exploit this vulnerability remotely without authentication. The attack complexity is low. [1] By sending crafted HTTP requests to the login page, the attacker can inject malicious SQL code. [1] This is a blind SQL injection, meaning the attacker may need to infer results based on application responses.

Impact

Successful exploitation allows an attacker to extract sensitive information from the database, perform unauthorized actions, and potentially execute arbitrary SQL queries. [1] This could lead to unauthorized access, data leakage, or disruption of critical industrial processes. [1] The CVSS v3 base score is 9.8 (Critical) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. [1]

Mitigation

As of the advisory, ARDEREG was aware of the issue but had not responded to CISA's requests. [1] ARDEREG recommends security awareness and training as a workaround. [1] No patch is available yet.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.