← volver
CVE-2018-15447

Cisco Integrated Management Controller Supervisor SQL Injection Vulnerability

CVSS 6.5 MEDIUMEPSS 1.7%CWE-89
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 1.7%KEV nãoPoC Nuclei Metasploit Patch referenciado
Ciclo de vida
08 nov 2018Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →