S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 7, 2024

CVE-2024-8877 Scanner

CVE-2024-8877 scanner - SQL Injection vulnerability in Riello Netman 204

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-8877
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Netman 204by Riello
0
netman_204_firmwareby riello-ups
0
Updated Aug 22, 2026View on NVD →
Detail

Riello Netman 204 is a firmware used in network interfaces by Riello UPS systems. This system provides remote monitoring and control, commonly deployed by IT teams in data centers to manage power systems effectively. Netman 204 facilitates real-time log data on power system status, events, and controls for network-connected UPS units. The firmware plays a key role in maintaining continuity by allowing admins to respond to power-related issues remotely. It is especially useful in enterprise and industrial environments where constant uptime is critical.

The CVE-2024-8877 vulnerability in Riello Netman 204 allows unauthorized SQL injection through specific endpoints. This injection vulnerability affects log data storage endpoints, enabling malicious actors to manipulate the data. An attacker exploiting this vulnerability could alter or damage log records without authentication. This flaw poses a critical risk as it can interfere with data integrity and impact incident response.

The SQL injection vulnerability in Riello Netman 204 exists in the endpoints /cgi-bin/db_datalog_w.cgi, /cgi-bin/db_eventlog_w.cgi, and /cgi-bin/db_multimetr_w.cgi. These endpoints accept input data but lack sufficient input sanitization, allowing SQL queries to be embedded and executed. The parameters in the query, especially those related to date and gravity type, can be modified to inject malicious SQL code. An attacker exploiting this vulnerability could modify or delete important log data. This issue is critical as it is exploitable without requiring authentication, allowing any attacker to potentially compromise the integrity of log information remotely.

Exploiting this vulnerability allows malicious actors to modify or corrupt system logs, leading to a loss of data integrity. This could make it challenging for system administrators to respond accurately to incidents, as logs may contain manipulated information. In severe cases, it could prevent the detection of other ongoing attacks, as corrupted logs mask evidence of unauthorized activities. Furthermore, altered logs can lead to compliance violations if accurate record-keeping is a regulatory requirement.

With S4E’s comprehensive platform, you can continuously monitor for vulnerabilities in your networked devices, like Riello Netman 204, and receive detailed alerts. Our platform provides access to cutting-edge detection tools and insights, helping you address vulnerabilities like SQL Injection before they lead to serious incidents. By joining, you can secure a robust defense against known and emerging threats and benefit from ongoing vulnerability management tailored to your assets. Protect your digital landscape effortlessly with S4E’s extensive threat detection and risk assessment capabilities.

References:

Solution Advice
  • Implement immediate firmware updates that patch the SQL injection vulnerability.
  • Enable input sanitization and validation to prevent injection of malicious SQL commands.
  • Limit access to critical endpoints by using strong authentication mechanisms.
  • Monitor and regularly audit logs for unexpected entries or tampering.
  • Use network-layer protections, such as web application firewalls (WAF), to detect and block injection attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.