Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-12619


A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.


Published

2020-01-26T05:15:10.817

Last Modified

2024-11-21T04:23:12.100

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System cisco sd-wan_firmware ≤ 17.2.0 Yes
Hardware cisco vedge-100 - No
Hardware cisco vedge-1000 - No
Hardware cisco vedge-100b - No
Hardware cisco vedge-2000 - No
Hardware cisco vedge-5000 - No
Hardware cisco vedge_100m - No
Hardware cisco vedge_100wm - No

References