{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-16T17:54:06.938","vulnerabilities":[{"cve":{"id":"CVE-2012-6427","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2012-12-23T21:55:01.547","lastModified":"2025-07-01T20:15:24.093","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Carlo Gavazzi \nEOS-Box\n\ndoes not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality."},{"lang":"es","value":"Múltiples vulnerabilidades de inyección SQL en Carlo Gavazzi EOS-Box con firmware antes de v1.0.0.1080_2.1.10 permiten a atacantes remotos ejecutar comandos SQL a través de vectores no especificados. Se trata de un problema similar a CVE-2012-5861.\r\n"}],"metrics":{"cvssMetricV2":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-89"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:carlosgavazzi:eos-box_photovoltaic_monitoring_system_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.0","matchCriteriaId":"61868231-4AC6-476D-8A7F-0520E46044F0"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:carlosgavazzi:eos-box_photovoltaic_monitoring_system:-:*:*:*:*:*:*:*","matchCriteriaId":"66B585E4-5C68-49BB-BD40-8D166067D32A"}]}]}],"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-12-354-02","source":"ics-cert@hq.dhs.gov"},{"url":"http://www.us-cert.gov/control_systems/pdf/ICSA-12-354-02.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"]}]}}]}