CVE-2016-1442
published 2016-07-07CVE-2016-1442: The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted…
PriorityP357high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
3.20%
86.7th percentile
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure | — | — |
| cisco | prime_infrastructure_administrative | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
vendor_cisco4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Prime Infrastructure Administrative Web Interface HTML Injection Vulnerability
vendor_cisco·2016-07-06·CVSS 4.0
CVE-2016-1442 [MEDIUM] CWE-20 Cisco Prime Infrastructure Administrative Web Interface HTML Injection Vulnerability
Cisco Prime Infrastructure Administrative Web Interface HTML Injection Vulnerability
A vulnerability in the administrative web interface of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to execute arbitrary commands on the affected system and on the devices managed by the system.
The vulnerability is due to improper user input validation. An attacker could exploit this vulnerability by inserting crafting input into the affected fields of the web interface.
Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160706-pi
Cisco
Cisco Prime Infrastructure Administrative Web Interface HTML Injection Vulnerability
vendor_cisco
CVE-2016-1442 Cisco Prime Infrastructure Administrative Web Interface HTML Injection Vulnerability
CVE-2016-1442: Cisco Prime Infrastructure Administrative Web Interface HTML Injection Vulnerability
A vulnerability in the administrative web interface of Cisco Prime Infrastructure (PI) could allow an authenticated, remote attacker to execute arbitrary commands on the affected system and on the devices managed by the system. The vulnerability is due to improper user input validation. An attacker could exploit this vulnerability by inserting crafting input into the affected fields of the web interface. Cisco has not released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCuy96280
GHSA
GHSA-4xcw-6wfp-8h2m: The administrative web interface in Cisco Prime Infrastructure (PI) before 3
ghsa_unreviewed·2022-05-14
CVE-2016-1442 [HIGH] CWE-20 GHSA-4xcw-6wfp-8h2m: The administrative web interface in Cisco Prime Infrastructure (PI) before 3
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-07-07
Published