Multiple Cisco Products Multiple SQL Injection Vulnerabilities
BID:108337
CVE-2019-1824 | CVE-2019-1825 |Info
Multiple Cisco Products Multiple SQL Injection Vulnerabilities
| Bugtraq ID: | 108337 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-1824 CVE-2019-1825 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2019 12:00AM |
| Updated: | May 15 2019 12:00AM |
| Credit: | Steven Seeley (mr_me) of Source Incite. |
| Vulnerable: |
Cisco Prime Infrastructure 3.4 Cisco Evolved Programmable Network Manager 3.0 |
| Not Vulnerable: |
Cisco Prime Infrastructure 3.4.1 Cisco Prime Infrastructure 3.6 Cisco Prime Infrastructure 3.5 Cisco Evolved Programmable Network Manager 3.0.1 |
Discussion
Multiple Cisco Products Multiple SQL Injection Vulnerabilities
Cisco Prime Infrastructure and Evolved Programmable Network Manager are prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker can leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is tracked by Cisco Bug ID's CSCvo23576, CSCvo28734, CSCvo62268 and CSCvo62275.
The following Cisco products are vulnerable:
Cisco Prime Infrastructure versions prior to 3.4.1, 3.5, and 3.6 are vulnerable
Cisco Evolved Programmable Network Manager versions prior to 3.0.1 are vulnerable
Cisco Prime Infrastructure and Evolved Programmable Network Manager are prone to multiple SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query.
An attacker can leverage this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is tracked by Cisco Bug ID's CSCvo23576, CSCvo28734, CSCvo62268 and CSCvo62275.
The following Cisco products are vulnerable:
Cisco Prime Infrastructure versions prior to 3.4.1, 3.5, and 3.6 are vulnerable
Cisco Evolved Programmable Network Manager versions prior to 3.0.1 are vulnerable
Exploit / POC
Multiple Cisco Products Multiple SQL Injection Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Cisco Products Multiple SQL Injection Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Cisco Products Multiple SQL Injection Vulnerabilities
References:
References: