#VU26221 SQL injection in Cisco SD-WAN and Cisco vManage Network Management Software - CVE-2019-16012

 

#VU26221 SQL injection in Cisco SD-WAN and Cisco vManage Network Management Software - CVE-2019-16012

Published: March 19, 2020


Vulnerability identifier: #VU26221
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-16012
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco SD-WAN
Cisco vManage Network Management Software
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.

The vulnerability exists due to insufficient sanitization of user-supplied data in the web UI. A remote authenticated attacker can send a specially crafted request to the affected application and modify values on, or return values from, the underlying database as well as the operating system.


Remediation

Install updates from vendor's website.

External links