CVE-2018-25333
8.2nordex-online · N149 Wind Turbine Web Server
The nordex-online N149 Wind Turbine Web Server versions 4.0 through 4.5 are susceptible to an unauthenticated SQL injection vulnerability.
Executive summary
An unauthenticated SQL injection vulnerability in the nordex-online N149 Wind Turbine Web Server (v4.0-4.5) allows for unauthorized database interaction.
Vulnerability
The application is vulnerable to SQL injection (CWE-89) due to insufficient sanitization of input data. The vulnerability is exploitable by an unauthenticated remote attacker, enabling them to manipulate database queries.
Business impact
The ability to perform unauthorized SQL operations against critical infrastructure control software represents a severe risk to operational integrity. With a CVSS score of 8.2, this flaw could lead to unauthorized data access or disruption of turbine monitoring services, potentially causing significant operational downtime or safety risks.
Remediation
Immediate Action: Consult the vendor (nordex-online) for official firmware or software updates to remediate the vulnerability.
Proactive Monitoring: Review web server and database logs for anomalous activity, specifically looking for SQL syntax errors or unexpected query structures.
Compensating Controls: Isolate the turbine management interface within a secure, segmented network and utilize a WAF or NIDS to filter malicious traffic targeting the web interface.
Exploitation status
Public Exploit Available: Yes — a public exploit exists via ExploitDB (EDB-44684).
Analyst recommendation
Operators of N149 Wind Turbine systems must treat this as a high-priority risk. Given the potential for operational impact, ensure all management interfaces are secured and apply necessary vendor updates as soon as they are made available to mitigate the threat of unauthorized access.