PT-2016-2114 · Cisco · Cisco Evolved Programmable Network Manager+1

Publicado

2016-05-25

·

Atualizado

2019-07-29

·

CVE-2016-1406

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure versions prior to 3.1 Cisco Evolved Programmable Network Manager versions prior to 1.2.4
Description The issue is related to a lack of proper access control in the API web interface, allowing remote authenticated users to bypass intended Role-Based Access Control (RBAC) restrictions. This can be achieved by sending crafted JSON data, potentially leading to the disclosure of sensitive information and privilege escalation.
Recommendations For Cisco Prime Infrastructure versions prior to 3.1, update to version 3.1 or later. For Cisco Evolved Programmable Network Manager versions prior to 1.2.4, update to version 1.2.4 or later. As a temporary workaround, consider restricting access to the API web interface until a patch is available.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01467
CVE-2016-1406

Produtos afetados

Cisco Evolved Programmable Network Manager
Cisco Prime Infrastructure