CVE-2021-1225
published 2021-01-20CVE-2021-1225: Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL…
PriorityP359critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
1.39%
69.5th percentile
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulnerabilities by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_sd-wan_vmanage | — | — |
| cisco | sd-wan_vmanage | < 19.2.3 | 19.2.3 |
| cisco | sd-wan_vmanage | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco SD-WAN vManage SQL Injection Vulnerabilities
vendor_cisco·2021-01-20·CVSS 6.5
CVE-2021-1225 [MEDIUM] CWE-89 Cisco SD-WAN vManage SQL Injection Vulnerabilities
Cisco SD-WAN vManage SQL Injection Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system.
These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulnerabilities by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is ava
Cisco
Cisco SD-WAN vManage SQL Injection Vulnerabilities
vendor_cisco·CVSS 3.0
CVE-2021-1225 Cisco SD-WAN vManage SQL Injection Vulnerabilities
CVE-2021-1225: Cisco SD-WAN vManage SQL Injection Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulnerabilities by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system. Cisco has released software updates that address these vulnerabilities. There are no
CVSS: 3.0
CWE: CWE-89, CWE-89
Bug IDs: CSCvi59726, CSCv
GHSA
GHSA-fp36-mxpm-8r2j: Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to con
ghsa_unreviewed·2022-05-24
CVE-2021-1225 [CRITICAL] CWE-89 GHSA-fp36-mxpm-8r2j: Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to con
Multiple vulnerabilities in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected system.
These vulnerabilities exist because the web-based management interface improperly validates values in SQL queries. An attacker could exploit these vulnerabilities by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on or return values from the underlying database or the operating system.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-20
Published