| Publisher: Weidmueller Interface GmbH & Co. KG | Document category: csaf_security_advisory |
| Initial release date: 2026-07-28T09:00:00.000Z | Engine: psirt-advisory-engine 2.0 |
| Current release date: 2026-07-28T09:00:00.000Z | Build Date: 2026-07-21T13:00:00.000Z |
| Current version: 1.0.0 | Status: final |
| CVSSv3.1 Base Score: 9.8 | Severity: High |
| Original language: | Language: en-GB |
| Also referred to: VDE-2026-085, WMSA-2600003 | |
A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
As a general security measure, Weidmueller strongly recommends to change the default passwords and to minimize the network exposure of products. Limit access to trusted networks by using the appropriate mechanisms.
Successful exploitation allows an unauthenticated attacker to read, modify or delete data and to execute arbitrary SQL commands, potentially leading to further compromise of the underlying system.
It is strongly advised to update PROCON-WEB SCADA to version 6.11.3.
| Product | Affected Version | Fixed Version |
|---|---|---|
| PROCON-WEB SCADA | <=6.11.2 | 6.11.3 |
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
| CVSS Score: | 9.8 (CRITICAL) - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
|---|---|
| CWE: | CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
Known affected
Fixed
Update PROCON-WEB SCADA to version 6.11.3.
References
Namespace: https://www.weidmueller.com
psirt@weidmueller.com
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1.0.0 | 2026-07-28T09:00:00.000Z | Initial version |
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/