MEDIUM · 5.0

CVE-2011-2546

SQL injection vulnerability in the web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote attackers to execute arbitrary SQL commands via u...

Vulnerability Description

SQL injection vulnerability in the web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtq65669.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
CiscoSa500 Software<= 2.1.18
CiscoSa520All versions
CiscoSa520WAll versions
CiscoSa540All versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-2546?

CVE-2011-2546 is a vulnerability with a CVSS score of 5.0 (MEDIUM). SQL injection vulnerability in the web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote attackers to execute arbitrary SQL commands via u...

How severe is CVE-2011-2546?

CVE-2011-2546 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-2546?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Sa500 Software, Cisco Sa520, Cisco Sa520W, Cisco Sa540.