CVE-2016-1408
published 2016-07-02CVE-2016-1408: Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary…
PriorityP355high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
2.49%
82.8th percentile
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | evolved_programmable_network_manager | — | — |
| cisco | evolved_programmable_network_manager | — | — |
| cisco | evolved_programmable_network_manager | — | — |
| cisco | evolved_programmable_network_manager | — | — |
| cisco | evolved_programmable_network_manager | — | — |
| cisco | evolved_programmable_network_manager | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure_and_evolved_programmable_network_manager_authenticated | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_cisco6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcfc-q3x9-gc6f: Cisco Prime Infrastructure 1
ghsa_unreviewed·2022-05-14
CVE-2016-1408 [HIGH] CWE-20 GHSA-hcfc-q3x9-gc6f: Cisco Prime Infrastructure 1
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability
vendor_cisco·2016-06-29·CVSS 6.5
CVE-2016-1408 [MEDIUM] CWE-20 Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability
Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability
A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files and execute commands as the prime web user. The prime web user does not have the full privileges of root.
The vulnerability is due to incomplete input validation of HTTP requests. An attacker could exploit this vulnerability by authenticating to the application and sending a crafted HTTP request to the affected system. An exploit could allow the attacker to upload arbitrary files and execute commands as the prime web user.
Cisco has not released software updates that address this v
Cisco
Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability
vendor_cisco
CVE-2016-1408 Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability
CVE-2016-1408: Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability
A vulnerability in the web interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files and execute commands as the prime web user. The prime web user does not have the full privileges of root . The vulnerability is due to incomplete input validation of HTTP requests. An attacker could exploit this vulnerability by authenticating to the application and sending a crafted HTTP request to the affected system. An exploit could allow the attacker to upload arbitrary files and execute commands as the prime web user. Cisco has not released software updates that a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160629-pi-epnmhttp://www.securityfocus.com/bid/91506http://www.securitytracker.com/id/1036197http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160629-pi-epnmhttp://www.securityfocus.com/bid/91506http://www.securitytracker.com/id/1036197
2016-07-02
Published