← All CVEs

CVE-2019-16012

high · 8.1

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on, or return values from, the underlying database as well as the operating system.

8.1
CVSS
54.2%
EPSS (exploit prob.)
99th
EPSS percentile
2020-03-19
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-77CWE-89

Affected products

VendorProductAffected versions
ciscosd-wan_firmware< 19.2.2
cisco1100-4g_integrated_services_routerall versions
cisco1100-4gltegb_integrated_services_routerall versions
cisco1100-4gltena_integrated_services_routerall versions
cisco1100-6g_integrated_services_routerall versions
ciscovedge_100all versions
ciscovedge_1000all versions
ciscovedge_100ball versions
ciscovedge_100mall versions
ciscovedge_100wmall versions
ciscovedge_2000all versions
ciscovedge_5000all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2019-16012