CVE-2016-1320
published 2016-02-12CVE-2016-1320: The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug…
PriorityP433medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.36%
28.0th percentile
The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_collaboration | — | — |
| cisco | prime_collaboration | — | — |
| cisco | prime_collaboration | — | — |
| cisco | prime_collaboration_provisioning_local | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:L/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Collaboration Provisioning Local Privilege Escalation Vulnerability
vendor_cisco·2016-02-09·CVSS 4.3
CVE-2016-1320 [MEDIUM] CWE-264 Cisco Prime Collaboration Provisioning Local Privilege Escalation Vulnerability
Cisco Prime Collaboration Provisioning Local Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of the Cisco Prime Collaboration server could allow an authenticated, local attacker to access the underlying Linux operating system with the privileges of the root user.
The vulnerability is due to insufficient sanitization of user-supplied input. An attacker could exploit this vulnerability by bypassing policy restrictions and executing commands on the underlying operating system. The user needs to log in to the device with valid administrator-level credentials.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.
Cisco
Cisco Prime Collaboration Provisioning Local Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-1320 Cisco Prime Collaboration Provisioning Local Privilege Escalation Vulnerability
CVE-2016-1320: Cisco Prime Collaboration Provisioning Local Privilege Escalation Vulnerability
A vulnerability in the command-line interface (CLI) of the Cisco Prime Collaboration server could allow an authenticated, local attacker to access the underlying Linux operating system with the privileges of the root user. The vulnerability is due to insufficient sanitization of user-supplied input. An attacker could exploit this vulnerability by bypassing policy restrictions and executing commands on the underlying operating system. The user needs to log in to the device with valid administrator-level credentials. Cisco has released software updates that address this vulnerability.
CWE: CWE-264, CWE-264
Bug IDs: CSCux69286
GHSA
GHSA-9r6c-6xf4-89m9: The CLI in Cisco Prime Collaboration 9
ghsa_unreviewed·2022-05-17
CVE-2016-1320 [MEDIUM] CWE-78 GHSA-9r6c-6xf4-89m9: The CLI in Cisco Prime Collaboration 9
The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-02-12
Published