Eskom's vulnerability footprint centers on municipal and utility billing applications, including e-Belediye and water-meter reading systems that support public-facing service delivery. The observed weakness classes—spanning SQL injection, improper authorization, and incorrect use of privileged APIs—reflect common risks in web-based administrative and data-handling interfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eskom over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1863CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eskom Water Metering Software allows Command Line Execution through SQL Inject | Apr 14, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-1114CRITICAL Missing Authorization vulnerability in Eskom e-Belediye allows Information Elicitation.
This issue affects e-Belediye: from 1.0.0.95 before 1.0.0.100. | Mar 1, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-6151HIGH Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided by Users.
This issue affects e-municipality module: before v | Nov 28, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-6150HIGH Incorrect Use of Privileged APIs vulnerability in ESKOM Computer e-municipality module allows Collect Data as Provided by Users.
This issue affects e-municipality module: before v | Nov 28, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eskom.
Media articles that mention a CVE ID that affects a product developed by Eskom — matched by CVE ID, not by vendor name.