PT-2017-17293 · Cisco · Cisco Smart Net Total Care (Sntc) Software Collector Appliance

Published

2017-08-07

·

Updated

2019-10-09

·

CVE-2017-6754

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Smart Net Total Care (SNTC) Software Collector Appliance version 3.11
Description A vulnerability in the web-based management interface could allow an authenticated, remote attacker to perform a read-only, blind SQL injection attack. This could compromise the confidentiality of the system through SQL timing attacks due to insufficient input validation of certain user-supplied fields used to build SQL queries. An attacker could exploit this by submitting crafted URLs to the affected software, requiring multiple requests to execute an attack successfully. A successful exploit could allow the attacker to determine the presence of values in the SQL database.
Recommendations For Cisco Smart Net Total Care (SNTC) Software Collector Appliance version 3.11, consider restricting access to the web-based management interface until a fix is available. As a temporary workaround, avoid using user-supplied fields that are used to build SQL queries to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6754

Affected Products

Cisco Smart Net Total Care (Sntc) Software Collector Appliance