SQL Injection Vulnerability in Cisco Prime Infrastructure and Evolved Programmable Network Manager
CVE-2016-6443

8.8HIGH

Summary

A notable vulnerability has been identified in the Cisco Prime Infrastructure and Evolved Programmable Network Manager that permits an authenticated remote attacker to execute arbitrary SQL queries via the SQL database interface. This could potentially lead to system instability and compromise the confidentiality of the system's contents. Affected versions include Cisco Prime Infrastructure 3.1(0.128), 1.2(400), and 2.0(1.0.34A). For detailed guidance, refer to Cisco's advisory and associated references.

Affected Version(s)

Cisco Prime Infrastructure and Evolved Programmable Network Manager 3.1(0.128), 1.2(400), 2.0(1.0.34A) Cisco Prime Infrastructure and Evolved Programmable Network Manager 3.1(0.128), 1.2(400), 2.0(1.0.34A)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.