CVE-2025-2928

7.2

Genetec Inc. · Security Center

A SQL injection vulnerability exists in the Archiver role of Genetec Security Center, allowing an authenticated administrator to manipulate database queries.

Executive summary

A high-severity SQL injection vulnerability in Genetec Security Center allows authenticated attackers with administrative privileges to compromise the underlying database.

Vulnerability

This flaw, categorized as CWE-89, involves improper neutralization of special elements within SQL commands in the Archiver role. The CVSS vector indicates that while the vulnerability is network-accessible, it requires high-level administrative authentication to trigger.

Business impact

Successful exploitation allows an attacker to execute arbitrary SQL commands against the backend database, potentially leading to unauthorized data exfiltration, modification, or destruction of security system records. Given the CVSS score of 7.2, this vulnerability poses a significant risk to the integrity and confidentiality of the physical security infrastructure managed by the software.

Remediation

Immediate Action: Update Genetec Security Center to the fixed versions: 5.9.5.9, 5.10.4.28, 5.11.3.19, 5.12.2.6, 5.13.1.1, or any later release.

Proactive Monitoring: Review database access logs for anomalous, high-volume, or malformed queries originating from the service account associated with the Archiver role.

Compensating Controls: Ensure that the database service account operates under the principle of least privilege, restricting its permissions to only those necessary for its core functions to limit the potential impact of an injection attack.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing Genetec Security Center must prioritize the installation of the provided security updates. Because this vulnerability grants significant control over the application database, failure to patch could allow an attacker to bypass security controls entirely. Please verify your current version and apply the appropriate vendor-supplied fix as part of your next maintenance cycle.

More Genetec Inc. CVEs

Sources