Cisco Identity Services Engine CVE-2019-1942 SQL Injection Vulnerability
BID:109283
CVE-2019-1942 |Info
Cisco Identity Services Engine CVE-2019-1942 SQL Injection Vulnerability
| Bugtraq ID: | 109283 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-1942 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 17 2019 12:00AM |
| Updated: | Jul 17 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Cisco Identity Services Engine 2.6 Cisco Identity Services Engine 2.4(0.902) Cisco Identity Services Engine 2.3(0.904) |
| Not Vulnerable: | |
Discussion
Cisco Identity Services Engine CVE-2019-1942 SQL Injection Vulnerability
Cisco Identity Services Engine is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is being tracked by Cisco Bug ID CSCvp29278.
Cisco Identity Services Engine Software version 2.6.0 and prior are vulnerable.
Cisco Identity Services Engine is prone to an SQL-injection vulnerability.
A successful exploit may allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue is being tracked by Cisco Bug ID CSCvp29278.
Cisco Identity Services Engine Software version 2.6.0 and prior are vulnerable.
Exploit / POC
Cisco Identity Services Engine CVE-2019-1942 SQL Injection Vulnerability
Attacker can exploit this issue using a browser.
Attacker can exploit this issue using a browser.