CVE-2016-6443: SQL Injection
A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1.2(400), 2.0(1.0.34A).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6443?
CVE-2016-6443 has a medium severity rating due to its potential impact on system confidentiality and stability.
How do I fix CVE-2016-6443?
To fix CVE-2016-6443, it is recommended to update to the latest version of affected Cisco software, as detailed in security advisories.
Who is affected by CVE-2016-6443?
CVE-2016-6443 affects users of Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure versions 1.2 through 3.1.1.
What types of systems are impacted by CVE-2016-6443?
CVE-2016-6443 impacts systems using the SQL database interface within Cisco Prime Infrastructure and Evolved Programmable Network Manager.
Can CVE-2016-6443 be exploited remotely?
Yes, CVE-2016-6443 can be exploited by an authenticated, remote attacker to execute arbitrary SQL queries.