Are common database vulnerabilities a risk in the on-premise Box gateway?

There are no significant risks. SQLite 3.22.0 is used only for internal task queue management and includes only system-generated metadata (no video or images).

  1. There is no remote access to SQLite.
  2. There are no open inbound ports to attack.
  3. The SQLite database contains only task metadata generated by the firmware itself, so has no injection vulnerabilities.

As with any component of the Box gateway firmware, SQLite is automatically patched to address important CVE reports. However SQLite use is so constrained to its limited role in internal task queue management that its attack surface is negligible.



