Executive brief
NetBotz is a data center environmental monitoring and management system used to protect critical IT infrastructure. An authenticated user with web-service or web UI access could inject malicious database queries through Hibernate ORM, potentially allowing unauthorized access to sensitive facility and equipment data stored in the NetBotz database.
Technical details
This vulnerability is a SQL injection flaw in Hibernate Query Language (HQL) processing within the NetBotz application. The root cause involves insufficient input validation on HQL queries, allowing an authenticated attacker to inject malicious query syntax. The attack vector requires prior authentication via the NetBotz web-service interface or web UI. A successful exploit could enable an attacker to read, modify, or delete database records beyond their authorized scope. Patch status is not specified in the advisory.
Affected products
- Schneider Electric NetBotz
Timeline
- 2026-09-01: disclosed