Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-1297


The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST request, aka Bug ID CSCul84801.


Published

2016-02-26T05:59:00.130

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco application_control_engine_software a5\(1.0\) Yes
Application cisco application_control_engine_software a5\(1.1\) Yes
Application cisco application_control_engine_software a5\(1.2\) Yes
Application cisco application_control_engine_software a5\(2.0\) Yes
Application cisco application_control_engine_software a5\(2.1\) Yes
Application cisco application_control_engine_software a5\(2.1e\) Yes
Application cisco application_control_engine_software a5\(3.0\) Yes

References