CVE-2017-5814SQL Injection in Packard Enterprise Network Automation

CWE-89SQL Injection3 documents3 sources
Severity
9.8CRITICALNVD
EPSS
23.6%
top 4.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 14

Description

A remote sql injection authentication bypass in HPE Network Automation version 9.1x, 9.2x, 10.0x, 10.1x and 10.2x were found.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDhp/network_automation11 versions+10
CVEListV5hewlett_packard_enterprise/network_automation9.1x, 9.2x, 10.0x, 10.1x and 10.2x

🔴Vulnerability Details

2
GHSA
GHSA-2793-7v75-7pw5: A remote sql injection authentication bypass in HPE Network Automation version 92022-05-14
CVEList
CVE-2017-5814: A remote sql injection authentication bypass in HPE Network Automation version 92018-02-15
CVE-2017-5814 — SQL Injection | cvebase