PT-2016-6916 · Cisco · Cisco Evolved Programmable Network Manager+1
Publicado
2016-10-27
·
Atualizado
2019-08-01
·
CVE-2016-6443
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Prime Infrastructure and Evolved Programmable Network Manager versions 1.2(400), 2.0(1.0.34A), 3.1(0.128)
Description
A vulnerability in the SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries, potentially causing product instability.
Recommendations
For version 1.2(400), update to a version that includes the fix for this issue.
For version 2.0(1.0.34A), update to a version that includes the fix for this issue.
For version 3.1(0.128), update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the SQL database interface to minimize the risk of exploitation.
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cisco Prime Infrastructure
Cisco Evolved Programmable Network Manager