Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-1406


The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.


Published

2016-05-25T01:59:09.757

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco evolved_programmable_network_manager 1.2.0 Yes
Application cisco evolved_programmable_network_manager 1.2.1.3 Yes
Application cisco evolved_programmable_network_manager 1.2.200 Yes
Application cisco evolved_programmable_network_manager 1.2.300 Yes
Application cisco prime_infrastructure 1.2 Yes
Application cisco prime_infrastructure 1.2.0.103 Yes
Application cisco prime_infrastructure 1.2.1 Yes
Application cisco prime_infrastructure 1.3 Yes
Application cisco prime_infrastructure 1.3.0.20 Yes
Application cisco prime_infrastructure 1.4 Yes
Application cisco prime_infrastructure 1.4.0.45 Yes
Application cisco prime_infrastructure 1.4.1 Yes
Application cisco prime_infrastructure 1.4.2 Yes
Application cisco prime_infrastructure 2.0 Yes
Application cisco prime_infrastructure 2.1.0 Yes
Application cisco prime_infrastructure 2.2 Yes
Application cisco prime_infrastructure 2.2\(2\) Yes
Application cisco prime_infrastructure 3.0 Yes

References