CVE-2017-6698

MEDIUM

Cisco Prime Infrastructure and Evolved Programmable Network Manager - Authenticated SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitrary SQL queries, aka SQL Injection. More Information: CSCvc23892 CSCvc35270 CSCvc35626 CSCvc35630 CSCvc49568. Known Affected Releases: 3.1(1) 2.0(4.0.45B).

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038751
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99214

Scores

CVSS v3 5.4
EPSS 0.0094
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-89
Status published
Products (3)
cisco/prime_infrastructure 2.0\(4.0.45b\)
cisco/prime_infrastructure 3.1\(1\)
n/a/Cisco Prime Infrastructure and Evolved Programmable Network Manager Cisco Prime Infrastructure and Evolved Programmable Network Manager
Published Jul 04, 2017
Tracked Since Feb 18, 2026