Soitec SmartEnergy 1.4 SCADA Login SQL Injection Authentication Bypass

Soitec SmartEnergy web application suffers from an authentication bypass vulnerability using SQL Injection attack in the login script. The script fails to sanitize the ‘login’ POST parameter allowing the attacker to bypass the security mechanism and view sensitive information that can be further used in a social engineering attack. Versions 1.3 and 1.4 are affected.

Leave a Reply