PT-2016-2322 · Cisco · Cisco Evolved Programmable Network Manager+1

Publicado

2016-07-02

·

Atualizado

2019-07-29

·

CVE-2016-1408

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure versions 1.2 through 3.1 Evolved Programmable Network Manager (EPNM) versions 1.2 and 2.0
Description The issue exists due to insufficient input validation in the software, allowing a remote attacker to upload files or execute arbitrary commands using a specially crafted HTTP request.
Recommendations For Cisco Prime Infrastructure versions 1.2 through 3.1, update the software to a version that includes the necessary security patches. For Evolved Programmable Network Manager (EPNM) versions 1.2 and 2.0, update the software to a version that includes the necessary security patches. As a temporary workaround, consider restricting access to the affected HTTP endpoints to minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01711
CVE-2016-1408

Produtos afetados

Cisco Prime Infrastructure
Cisco Evolved Programmable Network Manager