Cisco Unified Intelligence Center < 12.6 / 12.6.x < 12.6(2) ES08 / 15.0.x < 15.0(1) SU2 SQL Injection (cisco-sa-cuic-sql-inject-2qbfWSm5)

medium Nessus Plugin ID 338752

Synopsis

The remote device is missing a vendor-supplied security patch.

Description

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to the relevant fixed version referenced in Cisco bug ID CSCwt51262.

See Also

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwt51262

http://www.nessus.org/u?e173d1a0

Plugin Details

Severity: Medium

ID: 338752

File Name: cisco-sa-cuic-sql-inject-2qbfWSm5.nasl

Version: 1.1

Type: Local

Family: CISCO

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

CVSS Score Source: CVE-2026-20327

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Vulnerability Information

CPE: cpe:/a:cisco:unified_intelligence_center

Required KB Items: installed_sw/Cisco Unified Intelligence Center (CUIC)

Patch Publication Date: 8/19/2026

Vulnerability Publication Date: 8/19/2026

Reference Information

CVE: CVE-2026-20327

CWE: 89

CISCO-SA: cisco-sa-cuic-sql-inject-2qbfWSm5

IAVA: 2026-A-0863

CISCO-BUG-ID: CSCwt51262