Unrated severityNVD Advisory· Published Jul 16, 2020· Updated Nov 13, 2024
Cisco SD-WAN vManage Software SQL Injection Vulnerability
CVE-2020-3468
Description
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates values within SQL queries. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.
Affected products
1- Range: n/a
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-v78FubGVmitrevendor-advisoryx_refsource_CISCO
News mentions
0No linked articles in our index yet.