CVE-2014-3326
published 2014-07-26CVE-2014-3326: SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via…
PriorityP341medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.06%
79.1th percentile
SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | security_manager | — | — |
| cisco | security_manager | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4cvf-2x9p-w298: SQL injection vulnerability in the web framework in Cisco Security Manager 4
ghsa_unreviewed·2022-05-17
CVE-2014-3326 [MEDIUM] CWE-89 GHSA-4cvf-2x9p-w298: SQL injection vulnerability in the web framework in Cisco Security Manager 4
SQL injection vulnerability in the web framework in Cisco Security Manager 4.5 and 4.6 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCup26957.
Cisco
Cisco Security Manager SQL Injection Vulnerability
vendor_cisco·2014-07-24·CVSS 6.5
CVE-2014-3326 [MEDIUM] CWE-89 Cisco Security Manager SQL Injection Vulnerability
Cisco Security Manager SQL Injection Vulnerability
A vulnerability in the web framework code of Cisco Security Manager could allow an authenticated, remote attacker to execute arbitrary queries on the database.
The vulnerability is due to insufficient controls on Structured Query Language (SQL) statements. An attacker could exploit this vulnerability by sending crafted requests to the web server. An exploit could allow the attacker to read a subset of the data stored in the database.
Cisco has confirmed the vulnerability in a security notice; however, software updates are not available.
To exploit this vulnerability, an attacker must authenticate to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
Cisco indicates through the CVSS score t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/60455http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3326http://tools.cisco.com/security/center/viewAlert.x?alertId=35029http://www.securityfocus.com/bid/68877http://www.securitytracker.com/id/1030639https://exchange.xforce.ibmcloud.com/vulnerabilities/94841http://secunia.com/advisories/60455http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3326http://tools.cisco.com/security/center/viewAlert.x?alertId=35029http://www.securityfocus.com/bid/68877http://www.securitytracker.com/id/1030639https://exchange.xforce.ibmcloud.com/vulnerabilities/94841
2014-07-26
Published