Home
CRITICAL: 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDefault status
unknown
IoTSuite SaaSComposer prior to version 3.4.15
affected
IoTSuite Growth Linux docker prior to version V2.0.2
affected
IoTSuite Starter Linux docker prior to version V2.0.2
affected
IoT Edge Linux docker prior to version V2.0.2
affected
IoT Edge Windows prior to version V2.0.2
affected
Description
Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet.
Product status
IoTSuite SaaSComposer prior to version 3.4.15
IoTSuite Growth Linux docker prior to version V2.0.2
IoTSuite Starter Linux docker prior to version V2.0.2
IoT Edge Linux docker prior to version V2.0.2
IoT Edge Windows prior to version V2.0.2
Credits
Loi Nguyen Thang
References
www.csa.gov.sg/...-and-advisories/alerts/alerts-al-2026-001/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.