PatchSiren cyber security CVE debrief
CVE-2022-45089 Gruparge CVE debrief
CVE-2022-45089 is a HIGH severity SQL Injection vulnerability (CVSS 3.1: 8.8) affecting Gruparge Smartpower Web, an energy and control systems management platform. The vulnerability stems from improper input validation, allowing authenticated attackers with low privileges to execute arbitrary SQL commands. The issue affects all versions prior to 23.01.01. This CVE was published on 2023-02-12 and last modified on 2026-05-18. The vulnerability has been assigned CWE-89 (SQL Injection) by both NVD and the Turkish National Cyber Security Incident Response Center (USOM). No known exploitation in ransomware campaigns has been documented, and the vulnerability is not listed in CISA KEV.
- Vendor
- Gruparge
- Product
- Smartpower Web
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-02-12
- Original CVE updated
- 2026-05-18
- Advisory published
- 2023-02-12
- Advisory updated
- 2026-05-18
Who should care
Organizations operating Gruparge Smartpower Web for energy and control systems management, particularly in critical infrastructure environments. Security teams responsible for industrial control system (ICS) security, database administrators, and compliance officers in energy sector organizations should prioritize assessment and remediation.
Technical summary
The vulnerability exists due to insufficient input validation in the Smartpower Web application, allowing attackers to inject malicious SQL statements. With network access and low-privilege authentication, attackers can achieve high impact on confidentiality, integrity, and availability of the underlying database and application data. The attack complexity is low and requires no user interaction.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Gruparge Smartpower Web to version 23.01.01 or later to remediate the SQL injection vulnerability.
- Review and implement input validation and parameterized query patterns for all database interactions in Smartpower Web deployments.
- Monitor database query logs for anomalous SQL execution patterns that may indicate exploitation attempts.
- Apply principle of least privilege to database accounts used by the Smartpower Web application.
- If immediate patching is not feasible, implement Web Application Firewall (WAF) rules to detect and block common SQL injection payloads targeting the application.
Evidence notes
CVSS 3.1 vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. Affected CPE: cpe:2.3:a:gruparge:smartpower_web:*:*:*:*:*:*:*:* versions before 23.01.01. CWE-89 confirmed by both NVD and USOM sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2022-45089 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2022-45089
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2022-45089 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2022-45089
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0066
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0066
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.