CVE-2023-20110: Cisco Smart Software Manager On-Prem SQL Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability exists because the web-based management interface inadequately validates user input. An attacker could exploit this vulnerability by authenticating to the application as a low-privileged user and sending crafted SQL queries to an affected system. A successful exploit could allow the attacker to read sensitive data on the underlying database.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-20110.
What is the severity of CVE-2023-20110?
The severity of CVE-2023-20110 is medium with a CVSS score of 6.5.
What is the affected software for CVE-2023-20110?
The affected software for CVE-2023-20110 is Cisco Smart Software Manager On-Prem (SSM On-Prem) version up to exclusive 8-202303.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-89.
How can an authenticated, remote attacker exploit CVE-2023-20110?
An authenticated, remote attacker can exploit CVE-2023-20110 through SQL injection attacks on the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem).