CVE-2017-6698
MEDIUMCisco Prime Infrastructure and Evolved Programmable Network Manager - Authenticated SQL Injection
Title source: llmDescription
A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc23892 CSCvc35270 CSCvc35626 CSCvc35630 CSCvc49568. Known Affected Releases: 3.1(1) 2.0(4.0.45B).
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1038751
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/99214
Vendor Advisory x_refsource_confirm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piepnm2
Scores
CVSS v3
5.4
EPSS
0.0094
EPSS Percentile
57.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Details
CWE
CWE-89
Status
published
Products (3)
cisco/prime_infrastructure
2.0\(4.0.45b\)
cisco/prime_infrastructure
3.1\(1\)
n/a/Cisco Prime Infrastructure and Evolved Programmable Network Manager
Cisco Prime Infrastructure and Evolved Programmable Network Manager
Published
Jul 04, 2017
Tracked Since
Feb 18, 2026