CVE-2017-12731 is a critical SQL Injection vulnerability affecting OPW Fuel Management Systems SiteSentinel Integra 100, Integra 500, and iSite ATG consoles across several software versions. This flaw allows an unauthenticated attacker to inject malicious SQL queries, potentially leading to full compromise of the affected systems. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the high FAUCET Risk Score of 78/100 indicates its inherent danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 175CPE matchmatch criteria | cpe:2.3:o:opwglobal:sitesentinel_isite_atg_firmware:*:*:*:*:*:*:*:* | ||
16q3.1CPE matchmatch criteria | cpe:2.3:o:opwglobal:sitesentinel_isite_atg_firmware:16q3.1:*:*:*:*:*:*:* | ||
189CPE matchmatch criteria | cpe:2.3:o:opwglobal:sitesentinel_isite_atg_firmware:189:*:*:*:*:*:*:* | ||
191CPE matchmatch criteria | cpe:2.3:o:opwglobal:sitesentinel_isite_atg_firmware:191:*:*:*:*:*:*:* | ||
195CPE matchmatch criteria | cpe:2.3:o:opwglobal:sitesentinel_isite_atg_firmware:195:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.