The Samsung Integrated Management System DMS is used to manage several air conditioning units. The DMS contains a built-in web server that is susceptible to SQL injection attacks.
The DMS application's authentication form can be bypassed with SQL injection attacks. Versions 1.3.3, 1.4.1 and 1.4.2 are reported to be affected. Other versions may also be affected. More details can be found in ICS-CERT's 11-069-01 advisory.
An attacker can bypass authentication and access the web server as an administrative user.
Apply an Update
Thanks to José A. Guasch from SecurityByDefault.com for reporting this vulnerability.
|Date First Published:||2011-05-06|
|Date Last Updated:||2011-05-09 16:22 UTC|