VDE-2026-085
Last update
28.07.2026 11:00
Published at
28.07.2026 11:00
Vendor(s)
Weidmueller Interface GmbH & Co. KG
External ID
VDE-2026-085
CSAF Document
Summary
A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
Impact
Successful exploitation allows an unauthenticated attacker to read, modify or delete data and to execute arbitrary SQL commands, potentially leading to further compromise of the underlying system.
Affected Product(s)
| Model no. | Product name | Affected versions |
|---|---|---|
| 3173970000, 3173980000, 3173990000, 3174000000, 3174010000, 3174020000, 3174030000, 3174040000, 3174050000, 3174060000, 3174070000, 3174080000, 3174090000, 3174100000, 3174110000, 3174120000, 3174130000, 3174140000, 3174150000, 3174160000, 3174170000 | PROCON-WEB SCADA | vers:generic/>=1.0.0|<=6.11.2 |
Vulnerabilities
Expand / Collapse all
Published
28.07.2026 11:25
Severity
Weakness
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Summary
In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This allows a remote unauthenticated attacker to execute arbitrary SQL commands.
References
Remediation
It is strongly advised to update PROCON-WEB SCADA to version 6.11.3.
| Product | Affected Version | Fixed Version |
|---|---|---|
| PROCON-WEB SCADA | <=6.11.2 | 6.11.3 |
Acknowledgments
Weidmueller Interface GmbH & Co. KG thanks the following parties for their efforts:
- CERT@VDE for coordination (see https://certvde.com )
- Marcel Fromkorth (8com) for reporting the vulnerability (see https://www.8com.de )
Revision History
| Version | Date | Summary |
|---|---|---|
| 1.0.0 | 28.07.2026 11:00 | Initial version |