8.8
CVE-2016-1406
- EPSS 1.62%
- Veröffentlicht 25.05.2016 01:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Evolved Programmable Network Manager Version 1.2.0
Cisco ≫ Evolved Programmable Network Manager Version 1.2.1.3
Cisco ≫ Evolved Programmable Network Manager Version 1.2.200
Cisco ≫ Evolved Programmable Network Manager Version 1.2.300
Cisco ≫ Prime Infrastructure Version 1.2
Cisco ≫ Prime Infrastructure Version 1.2.0.103
Cisco ≫ Prime Infrastructure Version 1.2.1
Cisco ≫ Prime Infrastructure Version 1.3
Cisco ≫ Prime Infrastructure Version 1.3.0.20
Cisco ≫ Prime Infrastructure Version 1.4
Cisco ≫ Prime Infrastructure Version 1.4.0.45
Cisco ≫ Prime Infrastructure Version 1.4.1
Cisco ≫ Prime Infrastructure Version 1.4.2
Cisco ≫ Prime Infrastructure Version 2.0
Cisco ≫ Prime Infrastructure Version 2.1.0
Cisco ≫ Prime Infrastructure Version 2.2
Cisco ≫ Prime Infrastructure Version 3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.62% | 0.729 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160523-pi-epnm
http://www.securitytracker.com/id/1035948