CVE-2011-1653 describes multiple critical SQL injection vulnerabilities within the Unified Network Control (UNC) Server of CA Total Defense r12 prior to SE2. These flaws allow unauthenticated remote attackers to execute arbitrary SQL commands by manipulating various stored procedures, such as UnAssignFunctionalRoles and RegenerateReport. With a CVSS score of 10.0, the vulnerability presents a severe risk, enabling complete compromise of confidentiality, integrity, and availability. While not observed in active exploitation, public exploit code, including a Metasploit module, is available, and its high EPSS and FAUCET Risk Score indicate significant exploitability potential despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r12CPE matchmatch criteria | cpe:2.3:a:broadcom:total_defense:r12:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.