{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"Marcel Fromkorth (8com)","summary":"reporting the vulnerability","urls":["https://www.8com.de"]}],"aggregate_severity":{"namespace":"https://www.first.org/cvss/v3.1/specification-document#Qualitative-Severity-Rating-Scale","text":"High"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.","title":"Summary"},{"category":"general","text":"As a general security measure, Weidmueller strongly recommends to change the default passwords and to minimize the network exposure of products. Limit access to trusted networks by using the appropriate mechanisms.","title":"General Recommendation"},{"category":"description","text":"Successful exploitation allows an unauthenticated attacker to read, modify or delete data and to execute arbitrary SQL commands, potentially leading to further compromise of the underlying system.","title":"Impact"},{"category":"description","text":"It is strongly advised to update PROCON-WEB SCADA to version 6.11.3.\n\n| Product | Affected Version | Fixed Version |\n|---------|-----------------|----------------|\n| PROCON-WEB SCADA | <=6.11.2 | 6.11.3 |","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"psirt@weidmueller.com","name":"Weidmueller Interface GmbH & Co. KG","namespace":"https://www.weidmueller.com"},"references":[{"category":"external","summary":"Weidmueller Security Advisory Board","url":"https://support.weidmueller.com/support-center/popular-resources/security-advisory-board"},{"category":"external","summary":"CERT@VDE Security Advisories for Weidmueller","url":"https://certvde.com/de/advisories/vendor/weidmueller/"},{"category":"self","summary":"VDE-2026-085: Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA - HTML","url":"https://certvde.com/de/advisories/VDE-2026-085"},{"category":"self","summary":"VDE-2026-085: Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA - CSAF","url":"https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-085.json"}],"title":"Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA","tracking":{"aliases":["VDE-2026-085","WMSA-2600003"],"current_release_date":"2026-07-28T09:00:00.000Z","generator":{"date":"2026-07-21T13:00:00.000Z","engine":{"name":"psirt-advisory-engine","version":"2.0"}},"id":"VDE-2026-085","initial_release_date":"2026-07-28T09:00:00.000Z","revision_history":[{"date":"2026-07-28T09:00:00.000Z","number":"1.0.0","summary":"Initial version"}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"vers:generic/>=1.0.0|<=6.11.2","product":{"name":"PROCON-WEB SCADA <=6.11.2","product_id":"CSAFPID-51001","product_identification_helper":{"cpe":"cpe:2.3:a:weidmueller:procon-web_SCADA:*:*:*:*:*:*:*:*","model_numbers":["3173970000","3173980000","3173990000","3174000000","3174010000","3174020000","3174030000","3174040000","3174050000","3174060000","3174070000","3174080000","3174090000","3174100000","3174110000","3174120000","3174130000","3174140000","3174150000","3174160000","3174170000"]}}},{"category":"product_version","name":"6.11.3","product":{"name":"PROCON-WEB SCADA 6.11.3","product_id":"CSAFPID-52001","product_identification_helper":{"cpe":"cpe:2.3:a:weidmueller:procon-web_SCADA:6.11.3:*:*:*:*:*:*:*","model_numbers":["3173970000","3173980000","3173990000","3174000000","3174010000","3174020000","3174030000","3174040000","3174050000","3174060000","3174070000","3174080000","3174090000","3174100000","3174110000","3174120000","3174130000","3174140000","3174150000","3174160000","3174170000"]}}}],"category":"product_name","name":"PROCON-WEB SCADA"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"Weidmueller"}]},"vulnerabilities":[{"cve":"CVE-2026-16462","cwe":{"id":"CWE-89","name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"},"notes":[{"category":"description","text":"In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.","title":"CVE Description"}],"product_status":{"fixed":["CSAFPID-52001"],"known_affected":["CSAFPID-51001"]},"references":[{"category":"external","summary":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - 9.3 / Critical","url":"https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}],"remediations":[{"category":"vendor_fix","details":"Update PROCON-WEB SCADA to version 6.11.3.","product_ids":["CSAFPID-51001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"products":["CSAFPID-51001"]}],"title":"SQL injection via unauthenticated GetGridData endpoint"}]}