SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-42258

BQE BillQuick Web Suite SQL Injection Vulnerability

KEVCRITICAL 9.8EPSS 74.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
74.43% probability · 99th percentile
CISA KEV
Listed 3 November 2021 · due 17 November 2021 · used in ransomware campaigns
Weakness
CWE-89
Affected
bqe/billquick web suite
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2021-42258

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.