CVE-2015-6345
published 2015-10-30CVE-2015-6345: SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary…
PriorityP339medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.36%
68.5th percentile
SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuw24700.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | secure | — | — |
| cisco | secure_access_control_server | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Secure Access Control Server SQL Injection Vulnerability
vendor_cisco·2015-10-26·CVSS 4.0
CVE-2015-6345 [MEDIUM] CWE-89 Cisco Secure Access Control Server SQL Injection Vulnerability
Cisco Secure Access Control Server SQL Injection Vulnerability
A vulnerability in the Cisco Secure Access Control Server (ACS) interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries.
The vulnerability is due to a lack of input validation on user-supplied input within SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected system. A successful exploit could allow the attacker to determine the presence of certain values in the database.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.c
Cisco
Cisco Secure Access Control Server SQL Injection Vulnerability
vendor_cisco
CVE-2015-6345 Cisco Secure Access Control Server SQL Injection Vulnerability
CVE-2015-6345: Cisco Secure Access Control Server SQL Injection Vulnerability
A vulnerability in the Cisco Secure Access Control Server (ACS) interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries. The vulnerability is due to a lack of input validation on user-supplied input within SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected system. A successful exploit could allow the attacker to determine the presence of certain values in the database. Cisco has released software updates that address this vulnerability.
CWE: CWE-89, CWE-89
Bug IDs: CSCuw24700
GHSA
GHSA-5qp7-4xmp-929c: SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5
ghsa_unreviewed·2022-05-17
CVE-2015-6345 [MEDIUM] CWE-89 GHSA-5qp7-4xmp-929c: SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5
SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuw24700.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-10-30
Published