CVE-2016-1301
published 2016-02-07CVE-2016-1301: The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before…
PriorityP354high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.47%
82.7th percentile
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asa-cx_and_cisco_prime_security_manager | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | asa_cx_context-aware_security_software | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
| cisco | prime_security_manager | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_cisco8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco ASA-CX and Cisco Prime Security Manager Privilege Escalation Vulnerability
vendor_cisco·2016-02-04·CVSS 8.5
CVE-2016-1301 [HIGH] CWE-264 Cisco ASA-CX and Cisco Prime Security Manager Privilege Escalation Vulnerability
Cisco ASA-CX and Cisco Prime Security Manager Privilege Escalation Vulnerability
A vulnerability in the role-based access control of Cisco ASA-CX and Cisco Prime Security Manager (PRSM) could allow an authenticated, remote attacker to change the password of any user on the system.
The vulnerability exists because the password change request is not fully qualified. An authenticated attacker with a user role other than Administrator could exploit this vulnerability by sending a specially crafted HTTP request to the Cisco PRSM. An exploit could allow the attacker to change the password of any user on the system, including users with the Administrator role.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link: https://sec.clou
Cisco
Cisco ASA-CX and Cisco Prime Security Manager Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-1301 Cisco ASA-CX and Cisco Prime Security Manager Privilege Escalation Vulnerability
CVE-2016-1301: Cisco ASA-CX and Cisco Prime Security Manager Privilege Escalation Vulnerability
A vulnerability in the role-based access control of Cisco ASA-CX and Cisco Prime Security Manager (PRSM) could allow an authenticated, remote attacker to change the password of any user on the system. The vulnerability exists because the password change request is not fully qualified. An authenticated attacker with a user role other than Administrator could exploit this vulnerability by sending a specially crafted HTTP request to the Cisco PRSM. An exploit could allow the attacker to change the password of any user on the system, including users with the Administrator role. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: http
GHSA
GHSA-vj56-2v5w-wg83: The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9
ghsa_unreviewed·2022-05-17
CVE-2016-1301 [HIGH] CWE-284 GHSA-vj56-2v5w-wg83: The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-prsmhttp://www.securitytracker.com/id/1034926http://www.securitytracker.com/id/1034927http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-prsmhttp://www.securitytracker.com/id/1034926http://www.securitytracker.com/id/1034927
2016-02-07
Published