CVE-2022-24690 is a blind boolean-based SQL Injection vulnerability affecting DSK DSKNet versions 2.16.136.0 and 2.17.136.5, specifically within the PresAbs.php endpoint. This vulnerability allows unauthenticated attackers to extract sensitive information, such as user badge numbers and PIN codes, and potentially alter database data. Rated with a CVSS score of 8.2 (HIGH), it poses a significant risk due to its network-based attack vector and low attack complexity, enabling unauthenticated access to critical data. Currently, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has not been added to CISA's KEV catalog, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.16.136.0CPE matchmatch criteria | cpe:2.3:a:dsk:dsknet:2.16.136.0:*:*:*:*:*:*:* | ||
2.17.136.5CPE matchmatch criteria | cpe:2.3:a:dsk:dsknet:2.17.136.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.