PT-2016-6916 · Cisco · Cisco Evolved Programmable Network Manager+1

Publicado

2016-10-27

·

Atualizado

2019-08-01

·

CVE-2016-6443

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure and Evolved Programmable Network Manager versions 1.2(400), 2.0(1.0.34A), 3.1(0.128)
Description A vulnerability in the SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries, potentially causing product instability.
Recommendations For version 1.2(400), update to a version that includes the fix for this issue. For version 2.0(1.0.34A), update to a version that includes the fix for this issue. For version 3.1(0.128), update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the SQL database interface to minimize the risk of exploitation.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-6443

Produtos afetados

Cisco Prime Infrastructure
Cisco Evolved Programmable Network Manager