Impact
The vulnerability is a blind SQL injection in the web‑based management interface of Cisco Unified Intelligence Center caused by insufficient validation of user input. An attacker who has valid user credentials on the device can send crafted HTTP requests that allow them to read the contents of the internal database. The flaw is a classic SQL injection (CWE‑89).
Affected Systems
Cisco Unified Intelligence Center; the affected devices are those whose web management interface is reachable by authorized users. No specific product version information is listed in the vulnerability entry.
Risk and Exploitability
The associated CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Attack requires local authentication; an attacker with legitimate credentials can exploit the blind SQL injection to exfiltrate data from the internal database. Because the attack vector is local authenticated, the threat is limited to users who can log in, but still allows full read access to sensitive data.
OpenCVE Enrichment