CVE-2019-16012: Cisco SD-WAN Solution vManage SQL Injection Vulnerability
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on, or return values from, the underlying database as well as the operating system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-16012?
CVE-2019-16012 is a vulnerability in the web UI of Cisco SD-WAN Solution vManage software that allows an authenticated remote attacker to conduct SQL injection attacks.
How does CVE-2019-16012 affect Cisco SD-WAN Solution vManage software?
CVE-2019-16012 affects Cisco SD-WAN Solution vManage software by allowing an authenticated remote attacker to conduct SQL injection attacks.
What is the severity of CVE-2019-16012?
CVE-2019-16012 has a severity rating of 8.1 (High).
How can an attacker exploit CVE-2019-16012?
An attacker can exploit CVE-2019-16012 by taking advantage of the web UI's improper validation of SQL values.
Is there a fix available for CVE-2019-16012?
Yes, Cisco has released a security advisory with instructions to mitigate the vulnerability. Please refer to the reference link for more information.