CVE-2013-5525
published 2013-10-10CVE-2013-5525: SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary…
PriorityP339medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.32%
67.4th percentile
SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | identity_services_engine_software | <= 1.2 | — |
| cisco | identity_services_engine_software | — | — |
| cisco | identity_services_engine_software | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Identity Services Engine Blind SQL Injection Vulnerability
vendor_cisco·2013-10-09·CVSS 6.5
CVE-2013-5525 [MEDIUM] CWE-89 Cisco Identity Services Engine Blind SQL Injection Vulnerability
Cisco Identity Services Engine Blind SQL Injection Vulnerability
A vulnerability in the web framework of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity and availability of the affected system by executing arbitrary SQL queries.
The vulnerability is due to a failure to validate user-supplied input used in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs including SQL statements. An exploit could allow the attacker to modify or delete entries in some database tables, affecting the integrity and availability of some functions.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit the vulnerability, the attacker must be able to authenti
GHSA
GHSA-67q2-r7xw-j63p: SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1
ghsa_unreviewed·2022-05-17
CVE-2013-5525 [MEDIUM] CWE-89 GHSA-67q2-r7xw-j63p: SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1
SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/98167http://secunia.com/advisories/55098http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5525http://tools.cisco.com/security/center/viewAlert.x?alertId=31160http://www.securitytracker.com/id/1029156https://exchange.xforce.ibmcloud.com/vulnerabilities/87723http://osvdb.org/98167http://secunia.com/advisories/55098http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2013-5525http://tools.cisco.com/security/center/viewAlert.x?alertId=31160http://www.securitytracker.com/id/1029156https://exchange.xforce.ibmcloud.com/vulnerabilities/87723
2013-10-10
Published