ARDEREG Sistemas SCADA SQL Injection
Description
ARDEREG Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the database. In this case, the vulnerability could allow an attacker to execute arbitrary SQL queries through the login page, potentially leading to unauthorized access, data leakage, or even disruption of critical industrial processes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated blind SQL injection in ARDEREG Sistema SCADA Central login page (versions 2.203 and prior) allows remote attackers to execute arbitrary SQL queries.
Vulnerability
The vulnerability is an unauthenticated blind SQL injection in the login page of ARDEREG Sistema SCADA Central versions 2.203 and prior. [1] The login page fails to properly neutralize special elements used in SQL commands, allowing an attacker to manipulate SQL query logic. [1]
Exploitation
An attacker can exploit this vulnerability remotely without authentication. The attack complexity is low. [1] By sending crafted HTTP requests to the login page, the attacker can inject malicious SQL code. [1] This is a blind SQL injection, meaning the attacker may need to infer results based on application responses.
Impact
Successful exploitation allows an attacker to extract sensitive information from the database, perform unauthorized actions, and potentially execute arbitrary SQL queries. [1] This could lead to unauthorized access, data leakage, or disruption of critical industrial processes. [1] The CVSS v3 base score is 9.8 (Critical) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. [1]
Mitigation
As of the advisory, ARDEREG was aware of the issue but had not responded to CISA's requests. [1] ARDEREG recommends security awareness and training as a workaround. [1] No patch is available yet.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=2.203
- ARDEREG/Sistemas SCADAv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.