FlyCASS CASS and KCM systems did not correctly filter SQL queries, which
made them vulnerable to attack by outside attackers with no
authentication.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-49148 FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication.
Fixes

Solution

According to the researchers, the security gap in the FlyCASS online portal has been closed.


Workaround

No workaround given by the vendor.

References
Link Providers
https://ian.sh/tsa cve-icon cve-icon
History

Wed, 26 Nov 2025 00:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 03:15:00 +0900

Type Values Removed Values Added
First Time appeared Flycass
Flycass flycass
CPEs cpe:2.3:a:flycass:flycass:-:*:*:*:*:*:*:*
Vendors & Products Flycass
Flycass flycass

Fri, 06 Sep 2024 06:30:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Sep 2024 04:45:00 +0900

Type Values Removed Values Added
Description FlyCASS CASS and KCM systems did not correctly filter SQL queries, which made them vulnerable to attack by outside attackers with no authentication.
Title FlyCASS Cockpit Access Security System (CASS) SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-25T14:22:09.394Z

Reserved: 2024-09-03T16:28:03.405Z

Link: CVE-2024-8395

cve-icon Vulnrichment

Updated: 2024-09-05T20:28:14.335Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-05T20:15:05.743

Modified: 2024-09-19T17:53:45.753

Link: CVE-2024-8395

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses