7.5
CVSSv2

CVE-2013-1163

Published: 01/04/2013 Updated: 02/04/2013
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in the device-management implementation in Cisco Connected Grid Network Management System (CG-NMS) allow remote malicious users to execute arbitrary SQL commands via unspecified vectors, aka Bug IDs CSCue14553 and CSCue38746.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco connected grid network management system -

Vendor Advisories

A vulnerability in device management of the Cisco Connected Grid Network Management System (CG-NMS) could allow an unauthenticated, remote attacker to modify data in the CG-NMS database by using SQL injection The vulnerability is due to insufficient input validation An attacker could exploit this vulnerability by including SQL statements in an e ...