Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

HTTP:CISCO:SD-WAN-SVM-MUL

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Cisco SD-WAN Solution vManage Multiple Vulnerabilities

Release Date

2020/05/07

Update Number

3279

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+

HTTP: Cisco SD-WAN Solution vManage Multiple Vulnerabilities


This signature detects attempts to exploit a known vulnerability against Cisco SD-WAN Solution vManage. A successful attack can lead to multiple vulnerabilities.

Extended Description

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates SQL values. An attacker could exploit this vulnerability by authenticating to the application and sending malicious SQL queries to an affected system. A successful exploit could allow the attacker to modify values on, or return values from, the underlying database as well as the operating system.

Affected Products

  • Cisco sd-wan_firmware 16.12.1b
  • Cisco sd-wan_firmware 16.12.1d
  • Cisco sd-wan_firmware 16.12.1e
  • Cisco sd-wan_firmware 16.12.2r
  • Cisco sd-wan_firmware 17.2.0
  • Cisco sd-wan_firmware 17.2.10
  • Cisco sd-wan_firmware 17.2.4
  • Cisco sd-wan_firmware 17.2.5
  • Cisco sd-wan_firmware 17.2.6
  • Cisco sd-wan_firmware 17.2.7
  • Cisco sd-wan_firmware 17.2.8
  • Cisco sd-wan_firmware 17.2.9
  • Cisco sd-wan_firmware 18.3.0
  • Cisco sd-wan_firmware 18.3.1
  • Cisco sd-wan_firmware 18.3.3
  • Cisco sd-wan_firmware 18.3.3.1
  • Cisco sd-wan_firmware 18.3.4
  • Cisco sd-wan_firmware 18.3.5
  • Cisco sd-wan_firmware 18.3.6
  • Cisco sd-wan_firmware 18.3.7
  • Cisco sd-wan_firmware 18.3.8
  • Cisco sd-wan_firmware 18.4.0
  • Cisco sd-wan_firmware 18.4.1
  • Cisco sd-wan_firmware 18.4.3
  • Cisco sd-wan_firmware 18.4.302
  • Cisco sd-wan_firmware 18.4.303
  • Cisco sd-wan_firmware 18.4.4
  • Cisco sd-wan_firmware 18.4.5
  • Cisco sd-wan_firmware 19.1.0
  • Cisco sd-wan_firmware 19.2.0
  • Cisco sd-wan_firmware 19.2.1

References

  • CVE: CVE-2019-16010
  • CVE: CVE-2019-16012

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out