CVE-2018-15447
published 2018-11-08CVE-2018-15447: A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute…
PriorityP261critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
1.53%
73.3th percentile
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_integrated_management_controller_supervisor | — | — |
| cisco | integrated_management_controller_supervisor | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit attempts arrive as crafted HTTP URLs containing malicious SQL statements targeting the Cisco IMC Supervisor web framework ↗
- →The attack is unauthenticated — no session/auth token required; monitor for SQL injection patterns in URL parameters on the IMC Supervisor web interface from unauthenticated sources ↗
- ·No workarounds are available for this vulnerability; patching is the only mitigation ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Integrated Management Controller Supervisor SQL Injection Vulnerability
vendor_cisco·2018-11-07·CVSS 6.5
CVE-2018-15447 [MEDIUM] CWE-89 Cisco Integrated Management Controller Supervisor SQL Injection Vulnerability
Cisco Integrated Management Controller Supervisor SQL Injection Vulnerability
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries.
The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.
There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181107-cimc-sql-inject
Cisco
Cisco Integrated Management Controller Supervisor SQL Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-15447 Cisco Integrated Management Controller Supervisor SQL Injection Vulnerability
CVE-2018-15447: Cisco Integrated Management Controller Supervisor SQL Injection Vulnerability
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application. There are no
CVSS: 3.0
CWE: CWE-89, CWE-89
Bug IDs: CSCvm10518
GHSA
GHSA-f653-5jhj-f235: A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker t
ghsa_unreviewed·2022-05-13
CVE-2018-15447 [CRITICAL] CWE-89 GHSA-f653-5jhj-f235: A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker t
A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-11-08
Published