{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/procon-web-scada--6.11.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-16462"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PROCON-WEB SCADA \u003c= 6.11.2"],"_cs_severities":["critical"],"_cs_tags":["sql-injection","vulnerability","scada","critical-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Weidmueller Interface"],"content_html":"\u003cp\u003eCVE-2026-16462 identifies a critical SQL Injection vulnerability within Weidmueller Interface's PROCON-WEB SCADA versions up to 6.11.2. The vulnerability stems from improper input sanitization in the 'GetGridData' endpoint, allowing a remote and unauthenticated attacker to execute arbitrary SQL commands. This flaw presents a severe risk for industrial control systems, as successful exploitation could lead to unauthorized data access, modification, or even control over critical SCADA functions. The high CVSS base score of 9.8 indicates the extreme severity, enabling attackers to compromise the integrity and availability of industrial processes. Defenders should prioritize patching and monitoring for exploitation attempts against this endpoint.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated remote attacker identifies a PROCON-WEB SCADA instance with the vulnerable 'GetGridData' endpoint exposed.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP GET or POST request targeting the vulnerable endpoint, embedding SQL injection payloads within the parameters intended for 'GetGridData'.\u003c/li\u003e\n\u003cli\u003eThe PROCON-WEB SCADA application receives the request and, due to insufficient input validation and sanitization, processes the malicious SQL payload directly.\u003c/li\u003e\n\u003cli\u003eThe embedded SQL commands are executed by the underlying database, granting the attacker unauthorized access to, or modification of, the SCADA system's database.\u003c/li\u003e\n\u003cli\u003eDepending on the database configuration and attacker's capabilities, this can escalate to arbitrary command execution on the host operating system.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves data exfiltration, system control, or disrupts critical industrial processes by manipulating SCADA parameters or injecting malicious commands.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe impact of successful exploitation of CVE-2026-16462 is critical, primarily due to the nature of SCADA systems often controlling vital industrial processes and critical infrastructure. An attacker could gain unauthorized access to sensitive operational data, manipulate control parameters, or disrupt system availability. This could lead to production downtime, equipment damage, safety hazards, environmental incidents, or financial losses. While no specific number of victims or sectors were reported, any organization utilizing PROCON-WEB SCADA versions 6.11.2 or earlier is susceptible to severe operational and reputational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-16462 immediately by upgrading Weidmueller Interface PROCON-WEB SCADA to a version greater than 6.11.2, as specified in the CERT VDE advisory.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules in this brief to your SIEM and tune for your environment to detect attempts to exploit CVE-2026-16462.\u003c/li\u003e\n\u003cli\u003eReview webserver logs for unusual HTTP requests to the \u003ccode\u003e/GetGridData\u003c/code\u003e endpoint, specifically looking for SQL injection patterns in the URI query or request body.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T10:28:20Z","date_published":"2026-07-28T10:28:20Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16462-procon-web-scada/","summary":"CVE-2026-16462 describes a critical SQL Injection vulnerability in Weidmueller Interface's PROCON-WEB SCADA, where a remote unauthenticated attacker can execute arbitrary SQL commands via the 'GetGridData' endpoint due to improper input sanitization, potentially leading to full system compromise.","title":"CVE-2026-16462: SQL Injection Vulnerability in PROCON-WEB SCADA","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-16462-procon-web-scada/"}],"language":"en","title":"CraftedSignal Threat Feed - PROCON-WEB SCADA \u003c= 6.11.2","version":"https://jsonfeed.org/version/1.1"}