PT-2016-2322 · Cisco · Cisco Evolved Programmable Network Manager+1

Published

2016-07-02

·

Updated

2019-07-29

·

CVE-2016-1408

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Prime Infrastructure versions 1.2 through 3.1 Evolved Programmable Network Manager (EPNM) versions 1.2 and 2.0
Description The issue exists due to insufficient input validation in the software, allowing a remote attacker to upload files or execute arbitrary commands using a specially crafted HTTP request.
Recommendations For Cisco Prime Infrastructure versions 1.2 through 3.1, update the software to a version that includes the necessary security patches. For Evolved Programmable Network Manager (EPNM) versions 1.2 and 2.0, update the software to a version that includes the necessary security patches. As a temporary workaround, consider restricting access to the affected HTTP endpoints to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01711
CVE-2016-1408

Affected Products

Cisco Prime Infrastructure
Cisco Evolved Programmable Network Manager