CVE-2018-15441 describes a critical SQL injection vulnerability in Cisco Prime License Manager (PLM) that allows unauthenticated, remote attackers to execute arbitrary SQL queries. This flaw stems from insufficient input validation, enabling attackers to send crafted HTTP POST requests with malicious SQL statements. A successful exploit could lead to data modification or deletion within the PLM database, or even shell access with postgres user privileges. With a CVSS score of 9.8 (CRITICAL), this vulnerability poses a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation (KEV: No) and no public exploit code (Metasploit, Nuclei, ExploitDB: None), its high FAUCET Risk Score of 78/100 indicates its potential severity. Despite its critical nature, there is no community discussion or media coverage surrounding this CVE, suggesting a lack of public awareness. Organizations using Cisco Prime License Manager should prioritize patching to mitigate the risk of this unauthenticated SQL injection vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0.1, <= 11.5CPE matchmatch criteria | cpe:2.3:a:cisco:prime_license_manager:*:*:*:*:*:*:*:* | ||
11.5\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:prime_license_manager:11.5\(1\):su5:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.