CVE-2019-12619
Cisco SD-WAN Solution SQL Injection Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted input that includes SQL statements to an affected system. A successful exploit could allow the attacker to modify entries in some database tables, affecting the integrity of the data.
Una vulnerabilidad en la interfaz web para Cisco SD-WAN Solution vManage, podría permitir a un atacante remoto autenticado impactar la integridad de un sistema afectado mediante una ejecución de consultas SQL arbitrarias. La vulnerabilidad es debido a una comprobación insuficiente de las entradas suministradas por el usuario. Un atacante podría explotar esta vulnerabilidad mediante el envío de entradas diseñadas que incluyen sentencias SQL hacia un sistema afectado. Una explotación con éxito podría permitir al atacante modificar entradas en algunas tablas de la base de datos, afectando la integridad de los datos.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2019-06-04 CVE Reserved
- 2020-01-26 CVE Published
- 2024-11-15 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | <= 17.2.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " <= 17.2.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-100 Search vendor "Cisco" for product "Vedge-100" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | <= 17.2.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " <= 17.2.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-1000 Search vendor "Cisco" for product "Vedge-1000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | <= 17.2.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " <= 17.2.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-100b Search vendor "Cisco" for product "Vedge-100b" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | <= 17.2.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " <= 17.2.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-2000 Search vendor "Cisco" for product "Vedge-2000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | <= 17.2.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " <= 17.2.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge-5000 Search vendor "Cisco" for product "Vedge-5000" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | <= 17.2.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " <= 17.2.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100m Search vendor "Cisco" for product "Vedge 100m" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Sd-wan Firmware Search vendor "Cisco" for product "Sd-wan Firmware" | <= 17.2.0 Search vendor "Cisco" for product "Sd-wan Firmware" and version " <= 17.2.0" | - |
Affected
| in | Cisco Search vendor "Cisco" | Vedge 100wm Search vendor "Cisco" for product "Vedge 100wm" | - | - |
Safe
|