CVE detail
CVE-2020-13500 — CVE-2020-13500
Published 2020-09-24 · Modified 2026-06-17 · Vendor aveva · Product edna_enterprise_data_historian · Source nvd
CRITICAL
severity
CVSS-derived band
0.0291
EPSS probability
exploitation probability, 30d
86.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References