CVE-2016-1358
published 2016-03-03CVE-2016-1358: Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document…
PriorityP432medium6.4CVSS 3.0
AVNACHPRLUIRSUCHINAH
EPSS
1.29%
67.1th percentile
Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuw81497.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure_xml_external_entity | — | — |
CVSS provenance
nvdv3.06.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Infrastructure XML External Entity Denial of Service Vulnerability
vendor_cisco·2016-03-03·CVSS 5.5
CVE-2016-1358 [MEDIUM] CWE-119 Cisco Prime Infrastructure XML External Entity Denial of Service Vulnerability
Cisco Prime Infrastructure XML External Entity Denial of Service Vulnerability
A vulnerability in the web-based user interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to have read access to confidential information stored in the affected system. In addition, the attacker could cause a partial denial of service (DoS) condition due to manipulation of system resources.
The vulnerability is due to improper handling of XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by convincing the authenticated administrator of the affected system to import a crafted XML file. An exploit could allow the attacker to view confidential files or cause a DoS condition.
Cisco has not released software updates that address this
Cisco
Cisco Prime Infrastructure XML External Entity Denial of Service Vulnerability
vendor_cisco
CVE-2016-1358 Cisco Prime Infrastructure XML External Entity Denial of Service Vulnerability
CVE-2016-1358: Cisco Prime Infrastructure XML External Entity Denial of Service Vulnerability
A vulnerability in the web-based user interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to have read access to confidential information stored in the affected system. In addition, the attacker could cause a partial denial of service (DoS) condition due to manipulation of system resources. The vulnerability is due to improper handling of XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by convincing the authenticated administrator of the affected system to import a crafted XML file. An exploit could allow the attacker to view confidential files or cause a DoS condition. Cisco has not released software updates that a
GHSA
GHSA-w8jj-j97r-vm8v: Cisco Prime Infrastructure 2
ghsa_unreviewed·2022-05-14
CVE-2016-1358 [MEDIUM] CWE-119 GHSA-w8jj-j97r-vm8v: Cisco Prime Infrastructure 2
Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuw81497.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-03-03
Published