CVE-2020-3378: Cisco SD-WAN vManage Software SQL Injection Vulnerability
A vulnerability in the web-based management interface for Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-3378?
CVE-2020-3378 is a vulnerability in the web-based management interface for Cisco SD-WAN vManage Software that could allow an authenticated, remote attacker to execute arbitrary SQL queries.
How severe is CVE-2020-3378?
CVE-2020-3378 has a severity rating of 4.3 out of 10.
Which software versions are affected by CVE-2020-3378?
The affected software versions include Cisco SD-WAN vManage Software up to and including 18.4.5, and versions between 19.2.0 and 19.2.3.
What is the Common Weakness Enumeration (CWE) number for CVE-2020-3378?
The CWE number for CVE-2020-3378 is CWE-89.
Where can I find more information about CVE-2020-3378?
More information about CVE-2020-3378 can be found at the following link: [Cisco Security Advisory](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sivm-M8wugR9O).