← Vulnerability feed

Vulnerability record · CVE-2018-15447 · published 8 November 2018

CVE-2018-15447: Cisco integrated management controller sql injection vulnerability

Cisco · Integrated Management Controller

A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.

9.8 CVSS 3.0 Critical EPSS 1.7% · top 23.3% CWE-89 · SQL injection
9.8CVSS 3.0 base score, v2 7.5
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the web framework code of Cisco Integrated Management Controller (IMC) Supervisor could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The vulnerability is due to a lack of proper validation of user-supplied input in SQL queries. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious SQL statements to the affected application.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15447 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-3470Cisco enterprise nfv infrastructure software memory buffer overflow vulnerabilityMultiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to exec…EPSS 4.8%8.8CVE-2020-3371Cisco integrated management controller os command injection vulnerabilityA vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code …EPSS 1.9%8.0CVE-2019-1632Cisco integrated management controller cross-site request forgery vulnerabilityA vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker t…EPSS 0.55%6.7CVE-2019-1879Cisco unified computing system os command injection vulnerabilityA vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands …EPSS 0.42%6.5CVE-2019-1627Cisco integrated management controller os command injection vulnerabilityA vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unautho…EPSS 1.2%6.1CVE-2021-1397Cisco integrated management controller open redirect vulnerabilityA vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote…EPSS 0.83%5.5CVE-2019-1628Cisco integrated management controller vulnerabilityA vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to cause a buffer over…EPSS 0.39%5.5CVE-2019-1630Cisco integrated management controller memory buffer overflow vulnerabilityA vulnerability in the firmware signature checking program of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attack…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2018-15447), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.