8.8

CVE-2016-1406

The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CiscoPrime Infrastructure Version1.2
CiscoPrime Infrastructure Version1.2.0.103
CiscoPrime Infrastructure Version1.2.1
CiscoPrime Infrastructure Version1.3
CiscoPrime Infrastructure Version1.3.0.20
CiscoPrime Infrastructure Version1.4
CiscoPrime Infrastructure Version1.4.0.45
CiscoPrime Infrastructure Version1.4.1
CiscoPrime Infrastructure Version1.4.2
CiscoPrime Infrastructure Version2.0
CiscoPrime Infrastructure Version2.1.0
CiscoPrime Infrastructure Version2.2
CiscoPrime Infrastructure Version3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.529
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.