#VU48564 SQL injection in Cisco IoT Field Network Director - CVE-2020-26075
Published: November 18, 2020 / Updated: November 19, 2020
Cisco IoT Field Network Director
Cisco Systems, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the REST API. A remote authenticated attacker can send a specially crafted request to the affected application and gain access to the back-end database of the affected device.