Executive brief
Weidmueller PROCON-WEB SCADA, a software platform used for monitoring and controlling industrial processes, contains a critical security flaw. An unauthenticated attacker can remotely access the system to read, modify, or delete sensitive operational data. This could lead to a total loss of control over the industrial environment or significant operational downtime.
Technical details
A SQL injection vulnerability (CWE-89) exists in the 'GetGridData' endpoint of Weidmueller PROCON-WEB SCADA due to improper sanitization of user-supplied input. A remote, unauthenticated attacker can exploit this by sending specially crafted requests to the affected endpoint. Successful exploitation allows for the execution of arbitrary SQL commands, enabling the attacker to read, modify, or delete database records and potentially gain further access to the underlying system. The vulnerability affects versions 1.0.0 through 6.11.2 and is resolved in version 6.11.3.
Affected products
- Weidmueller Interface PROCON-WEB SCADA 1.0.0 to 6.11.2
Timeline
- 2026-07-28: disclosed
- 2026-07-28: advisory
- 2026-07-28: patched: Fixed in version 6.11.3