Impact
The vulnerability is a classic SQL injection flaw caused by improper neutralization of special elements used within SQL commands, classified as CWE-89. An attacker who can supply crafted input to the affected components can manipulate backend database queries. If the attacker succeeds, the flaw could lead to unauthorized data access, modification, or deletion, potentially leading to significant disruption of system operations.
Affected Systems
The flaw affects Cisco Crosswork Planning, a network planning solution from Cisco. No specific affected versions are disclosed, so any deployment of Cisco Crosswork Planning remains potentially vulnerable until the hardening release is applied.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity, and the EPSS score indicates a very low but non‑zero exploitation probability (<1%). The lack of a KEV listing does not reduce the risk of exploitation. Based on the description, it is inferred that the vulnerability could be exposed through web or API interfaces that accept user‑supplied input incorporated into SQL statements. Exploitation would require only valid user credentials or publicly accessible endpoints, making it a high‑risk threat for organizations running Cisco Crosswork Planning.
OpenCVE Enrichment