Cisco Unified Intelligence Center 的基于 Web 的管理界面中存在一个漏洞,允许经过身份验证的本地攻击者对受影响设备执行盲 SQL 注入攻击。 该漏洞是由于对用户提供的输入验证不足所致。攻击者可以通过向基于 Web 的管理界面发送构造好的请求来利用此漏洞。成功利用该漏洞后,攻击者可以读取受影响设备内部数据库的内容。要利用此漏洞,攻击者必须拥有受影响设备上的有效用户凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cisco | Cisco Unified Intelligence Center | 11.6(1) |
affected |
10.5(1) |
affected | ||
11.0(1) |
affected | ||
11.5(1) |
affected | ||
12.0(1) |
affected | ||
12.5(1) |
affected | ||
11.0(2) |
affected | ||
12.6(1) |
affected | ||
| … +27 more rows | |||
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Cisco | Cisco Unified Intelligence Center | 11.6(1) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-20030 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20358 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20357 | 10.0 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20317 | 10.0 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentic |
| CVE-2026-20315 | 10.0 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Co |
| CVE-2026-20231 | 9.9 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutraliz |
| CVE-2026-20359 | 9.9 CRITICAL | Cisco Crosswork Security Hardening Release: August 2026 |
| CVE-2026-20318 | 9.6 CRITICAL | Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Input Val |
| CVE-2026-20319 | 7.5 HIGH | Cisco Secure Workload Software Security Hardening Release August 2026 - Buffer Management |
| CVE-2026-20320 | 7.5 HIGH | Cisco BroadWorks OCI解析器XEE漏洞 |
| CVE-2026-20302 | 6.1 MEDIUM | Cisco RoomOS Stack Overflow Vulnerability |
| CVE-2026-20232 | 5.4 MEDIUM | Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability |
| CVE-2026-20177 | 5.3 MEDIUM | Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability |
| CVE-2026-20314 | 5.0 MEDIUM | Cisco Packaged Contact Center Enterprise & Cisco Unified Contact Center Enterprise Server- |
No comments yet