A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.
This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful exploit could allow the attacker to view data in some database tables on an affected device.
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Prime_infrastructure | Cisco | 2.0.0 (including) | 2.0.0 (including) |
Prime_infrastructure | Cisco | 2.0.10 (including) | 2.0.10 (including) |
Prime_infrastructure | Cisco | 2.0.39 (including) | 2.0.39 (including) |
Prime_infrastructure | Cisco | 2.1 (including) | 2.1 (including) |
Prime_infrastructure | Cisco | 2.1.0 (including) | 2.1.0 (including) |
Prime_infrastructure | Cisco | 2.1.1 (including) | 2.1.1 (including) |
Prime_infrastructure | Cisco | 2.1.2 (including) | 2.1.2 (including) |
Prime_infrastructure | Cisco | 2.1.56 (including) | 2.1.56 (including) |
Prime_infrastructure | Cisco | 2.2 (including) | 2.2 (including) |
Prime_infrastructure | Cisco | 2.2.0 (including) | 2.2.0 (including) |
Prime_infrastructure | Cisco | 2.2.1 (including) | 2.2.1 (including) |
Prime_infrastructure | Cisco | 2.2.1-update01 (including) | 2.2.1-update01 (including) |
Prime_infrastructure | Cisco | 2.2.2 (including) | 2.2.2 (including) |
Prime_infrastructure | Cisco | 2.2.2-update03 (including) | 2.2.2-update03 (including) |
Prime_infrastructure | Cisco | 2.2.2-update04 (including) | 2.2.2-update04 (including) |
Prime_infrastructure | Cisco | 2.2.3 (including) | 2.2.3 (including) |
Prime_infrastructure | Cisco | 2.2.3-update02 (including) | 2.2.3-update02 (including) |
Prime_infrastructure | Cisco | 2.2.3-update03 (including) | 2.2.3-update03 (including) |
Prime_infrastructure | Cisco | 2.2.3-update04 (including) | 2.2.3-update04 (including) |
Prime_infrastructure | Cisco | 2.2.3-update05 (including) | 2.2.3-update05 (including) |
Prime_infrastructure | Cisco | 2.2.3-update06 (including) | 2.2.3-update06 (including) |
Prime_infrastructure | Cisco | 2.2.4 (including) | 2.2.4 (including) |
Prime_infrastructure | Cisco | 2.2.5 (including) | 2.2.5 (including) |
Prime_infrastructure | Cisco | 2.2.7 (including) | 2.2.7 (including) |
Prime_infrastructure | Cisco | 2.2.8 (including) | 2.2.8 (including) |
Prime_infrastructure | Cisco | 2.2.9 (including) | 2.2.9 (including) |
Prime_infrastructure | Cisco | 2.2.10 (including) | 2.2.10 (including) |
Prime_infrastructure | Cisco | 3.0.0 (including) | 3.0.0 (including) |
Prime_infrastructure | Cisco | 3.0.1 (including) | 3.0.1 (including) |
Prime_infrastructure | Cisco | 3.0.2 (including) | 3.0.2 (including) |
Prime_infrastructure | Cisco | 3.0.3 (including) | 3.0.3 (including) |
Prime_infrastructure | Cisco | 3.0.4 (including) | 3.0.4 (including) |
Prime_infrastructure | Cisco | 3.0.5 (including) | 3.0.5 (including) |
Prime_infrastructure | Cisco | 3.0.6 (including) | 3.0.6 (including) |
Prime_infrastructure | Cisco | 3.0.7 (including) | 3.0.7 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack10 (including) | 3.1-device_pack10 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack11 (including) | 3.1-device_pack11 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack12 (including) | 3.1-device_pack12 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack13 (including) | 3.1-device_pack13 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack14 (including) | 3.1-device_pack14 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack15 (including) | 3.1-device_pack15 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack16 (including) | 3.1-device_pack16 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack4 (including) | 3.1-device_pack4 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack5 (including) | 3.1-device_pack5 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack6 (including) | 3.1-device_pack6 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack7 (including) | 3.1-device_pack7 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack8 (including) | 3.1-device_pack8 (including) |
Prime_infrastructure | Cisco | 3.1-device_pack9 (including) | 3.1-device_pack9 (including) |
Prime_infrastructure | Cisco | 3.1.0 (including) | 3.1.0 (including) |
Prime_infrastructure | Cisco | 3.1.1 (including) | 3.1.1 (including) |
Prime_infrastructure | Cisco | 3.1.2 (including) | 3.1.2 (including) |
Prime_infrastructure | Cisco | 3.1.3 (including) | 3.1.3 (including) |
Prime_infrastructure | Cisco | 3.1.4 (including) | 3.1.4 (including) |
Prime_infrastructure | Cisco | 3.1.5 (including) | 3.1.5 (including) |
Prime_infrastructure | Cisco | 3.1.6 (including) | 3.1.6 (including) |
Prime_infrastructure | Cisco | 3.1.7 (including) | 3.1.7 (including) |
Prime_infrastructure | Cisco | 3.2 (including) | 3.2 (including) |
Prime_infrastructure | Cisco | 3.2-device_pack1 (including) | 3.2-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.2-device_pack2 (including) | 3.2-device_pack2 (including) |
Prime_infrastructure | Cisco | 3.2-device_pack3 (including) | 3.2-device_pack3 (including) |
Prime_infrastructure | Cisco | 3.2-device_pack4 (including) | 3.2-device_pack4 (including) |
Prime_infrastructure | Cisco | 3.2.0-fips (including) | 3.2.0-fips (including) |
Prime_infrastructure | Cisco | 3.2.1 (including) | 3.2.1 (including) |
Prime_infrastructure | Cisco | 3.2.2 (including) | 3.2.2 (including) |
Prime_infrastructure | Cisco | 3.3-device_pack1 (including) | 3.3-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.3-device_pack2 (including) | 3.3-device_pack2 (including) |
Prime_infrastructure | Cisco | 3.3-device_pack3 (including) | 3.3-device_pack3 (including) |
Prime_infrastructure | Cisco | 3.3-device_pack4 (including) | 3.3-device_pack4 (including) |
Prime_infrastructure | Cisco | 3.3.0 (including) | 3.3.0 (including) |
Prime_infrastructure | Cisco | 3.3.0-update01 (including) | 3.3.0-update01 (including) |
Prime_infrastructure | Cisco | 3.3.1 (including) | 3.3.1 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack1 (including) | 3.4-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack10 (including) | 3.4-device_pack10 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack11 (including) | 3.4-device_pack11 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack2 (including) | 3.4-device_pack2 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack3 (including) | 3.4-device_pack3 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack4 (including) | 3.4-device_pack4 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack5 (including) | 3.4-device_pack5 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack6 (including) | 3.4-device_pack6 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack7 (including) | 3.4-device_pack7 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack8 (including) | 3.4-device_pack8 (including) |
Prime_infrastructure | Cisco | 3.4-device_pack9 (including) | 3.4-device_pack9 (including) |
Prime_infrastructure | Cisco | 3.4.0 (including) | 3.4.0 (including) |
Prime_infrastructure | Cisco | 3.4.1 (including) | 3.4.1 (including) |
Prime_infrastructure | Cisco | 3.4.1-update01 (including) | 3.4.1-update01 (including) |
Prime_infrastructure | Cisco | 3.4.1-update02 (including) | 3.4.1-update02 (including) |
Prime_infrastructure | Cisco | 3.4.2 (including) | 3.4.2 (including) |
Prime_infrastructure | Cisco | 3.4.2-update01 (including) | 3.4.2-update01 (including) |
Prime_infrastructure | Cisco | 3.5-device_pack1 (including) | 3.5-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.5-device_pack2 (including) | 3.5-device_pack2 (including) |
Prime_infrastructure | Cisco | 3.5-device_pack3 (including) | 3.5-device_pack3 (including) |
Prime_infrastructure | Cisco | 3.5-device_pack4 (including) | 3.5-device_pack4 (including) |
Prime_infrastructure | Cisco | 3.5.0 (including) | 3.5.0 (including) |
Prime_infrastructure | Cisco | 3.5.0-update01 (including) | 3.5.0-update01 (including) |
Prime_infrastructure | Cisco | 3.5.0-update02 (including) | 3.5.0-update02 (including) |
Prime_infrastructure | Cisco | 3.5.0-update03 (including) | 3.5.0-update03 (including) |
Prime_infrastructure | Cisco | 3.5.1 (including) | 3.5.1 (including) |
Prime_infrastructure | Cisco | 3.5.1-update01 (including) | 3.5.1-update01 (including) |
Prime_infrastructure | Cisco | 3.5.1-update02 (including) | 3.5.1-update02 (including) |
Prime_infrastructure | Cisco | 3.5.1-update03 (including) | 3.5.1-update03 (including) |
Prime_infrastructure | Cisco | 3.6-device_pack1 (including) | 3.6-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.6.0 (including) | 3.6.0 (including) |
Prime_infrastructure | Cisco | 3.6.0-update01 (including) | 3.6.0-update01 (including) |
Prime_infrastructure | Cisco | 3.6.0-update02 (including) | 3.6.0-update02 (including) |
Prime_infrastructure | Cisco | 3.6.0-update03 (including) | 3.6.0-update03 (including) |
Prime_infrastructure | Cisco | 3.6.0-update04 (including) | 3.6.0-update04 (including) |
Prime_infrastructure | Cisco | 3.7-device_pack1 (including) | 3.7-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.7-device_pack2 (including) | 3.7-device_pack2 (including) |
Prime_infrastructure | Cisco | 3.7.0 (including) | 3.7.0 (including) |
Prime_infrastructure | Cisco | 3.7.0-update03 (including) | 3.7.0-update03 (including) |
Prime_infrastructure | Cisco | 3.7.1 (including) | 3.7.1 (including) |
Prime_infrastructure | Cisco | 3.7.1-update01 (including) | 3.7.1-update01 (including) |
Prime_infrastructure | Cisco | 3.7.1-update02 (including) | 3.7.1-update02 (including) |
Prime_infrastructure | Cisco | 3.7.1-update03 (including) | 3.7.1-update03 (including) |
Prime_infrastructure | Cisco | 3.7.1-update04 (including) | 3.7.1-update04 (including) |
Prime_infrastructure | Cisco | 3.7.1-update05 (including) | 3.7.1-update05 (including) |
Prime_infrastructure | Cisco | 3.7.1-update06 (including) | 3.7.1-update06 (including) |
Prime_infrastructure | Cisco | 3.7.1-update07 (including) | 3.7.1-update07 (including) |
Prime_infrastructure | Cisco | 3.8-device_pack1 (including) | 3.8-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.8.0 (including) | 3.8.0 (including) |
Prime_infrastructure | Cisco | 3.8.0-update01 (including) | 3.8.0-update01 (including) |
Prime_infrastructure | Cisco | 3.8.0-update02 (including) | 3.8.0-update02 (including) |
Prime_infrastructure | Cisco | 3.8.1 (including) | 3.8.1 (including) |
Prime_infrastructure | Cisco | 3.8.1-update01 (including) | 3.8.1-update01 (including) |
Prime_infrastructure | Cisco | 3.8.1-update02 (including) | 3.8.1-update02 (including) |
Prime_infrastructure | Cisco | 3.8.1-update03 (including) | 3.8.1-update03 (including) |
Prime_infrastructure | Cisco | 3.8.1-update04 (including) | 3.8.1-update04 (including) |
Prime_infrastructure | Cisco | 3.9-device_pack1 (including) | 3.9-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.9.0 (including) | 3.9.0 (including) |
Prime_infrastructure | Cisco | 3.9.0-update01 (including) | 3.9.0-update01 (including) |
Prime_infrastructure | Cisco | 3.9.1 (including) | 3.9.1 (including) |
Prime_infrastructure | Cisco | 3.9.1-update01 (including) | 3.9.1-update01 (including) |
Prime_infrastructure | Cisco | 3.9.1-update02 (including) | 3.9.1-update02 (including) |
Prime_infrastructure | Cisco | 3.9.1-update03 (including) | 3.9.1-update03 (including) |
Prime_infrastructure | Cisco | 3.9.1-update04 (including) | 3.9.1-update04 (including) |
Prime_infrastructure | Cisco | 3.10 (including) | 3.10 (including) |
Prime_infrastructure | Cisco | 3.10-device_pack1 (including) | 3.10-device_pack1 (including) |
Prime_infrastructure | Cisco | 3.10-update01 (including) | 3.10-update01 (including) |
Prime_infrastructure | Cisco | 3.10.0 (including) | 3.10.0 (including) |
Prime_infrastructure | Cisco | 3.10.1 (including) | 3.10.1 (including) |
Prime_infrastructure | Cisco | 3.10.2 (including) | 3.10.2 (including) |
Prime_infrastructure | Cisco | 3.10.3 (including) | 3.10.3 (including) |
Prime_infrastructure | Cisco | 3.10.4 (including) | 3.10.4 (including) |
Prime_infrastructure | Cisco | 3.10.4-update01 (including) | 3.10.4-update01 (including) |
Prime_infrastructure | Cisco | 3.10.4-update02 (including) | 3.10.4-update02 (including) |
Prime_infrastructure | Cisco | 3.10.4-update03 (including) | 3.10.4-update03 (including) |
Prime_infrastructure | Cisco | 3.10.5 (including) | 3.10.5 (including) |
Prime_infrastructure | Cisco | 3.10.6 (including) | 3.10.6 (including) |
Prime_infrastructure | Cisco | 3.10.6-update01 (including) | 3.10.6-update01 (including) |