ZeroHour

CVE-2024-8877

large

Unauthenticated SQL Injection in Riello Netman 204 UPS Network Card

CVSS 4.0
6.9 medium
EPSS
77%p100
Published
()
Modified
AI analysis

CVE-2024-8877 is an unauthenticated SQL injection (CWE-89) in the Riello Netman 204 UPS network management card, affecting all firmware versions through 4.05. Per the CVSS 4.0 vector, it is reachable remotely over the network with no privileges or user interaction required, apparently by sending crafted requests to the card's management interface. The flaw is confined to the SQLite database that stores measurement data, so an attacker can read or tamper with that stored data (low confidentiality and integrity impact) without taking over the device or disrupting power availability. Any deployment running Netman 204 firmware 4.05 or earlier is affected, which spans a broad installed base of Riello UPS installations. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA KEV, but EPSS assigns a 77.3% probability of exploitation within 30 days (100th percentile), making prompt patching and exposure checks advisable.

What to do: Upgrade Netman 204 to a fixed firmware newer than 4.05 following Riello's advisory, since this data does not name a specific fixed version. Until patched, restrict access to the card's management interface (avoid direct internet exposure or port forwarding) and review device logs for unusual requests. Given the very high EPSS score, prioritize checking and patching internet-exposed devices first.

Affected
Riello UPS Netman 204 firmwareall versions through 4.05 (4.05 and earlier); no fixed version is named in the available data
Estimated exposure
largeplausibly tens of thousands of internet-exposed devices; installed base likely in the hundreds of thousands (Netman 204 is Riello's standard UPS network card) — Netman 204 is the long-standing standard SNMP/web management card shipped with many Riello UPS families, and management interfaces of such embedded devices are commonly port-forwarded to the internet (as recent tank-gauge disclosures at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

Vendors
riello-ups
Products
netman 204 firmware
Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news