CVE-2019-16012
Description
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on, or return values from, the underlying database as well as the operating system.
Risk Information
Base Score
8.1
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
7.193
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Cisco SD-WAN Solution vManage SQL Injection Vulnerability For Cisco SD-WAN | NCM |
| Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability (CVE-2019-16012) | NCM |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-1705297 | Security Update for Cisco SD-WAN sdwan-20.4(0.55) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234