HIGH✓ PATCH🇬🇧 English

CVE-2016-1290

CVSS 8.1v3.0pub. 2016-04-06upd. 2026-05-06

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.

oryginał EN
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
  • Cisco Evolved Programmable Network Manager

    APP
    Cisco
    1.2.0
  • Cisco Prime Infrastructure

    APP
    Cisco
    1.21.2.0.1031.2.11.31.3.0.201.41.4.0.451.4.11.4.22.02.1.02.2
  • Sun Opensolaris

    OS
    Sun
    snv_124
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2019-15958CRITICAL9.8PL ✓ten sam produkt

RCE z uprawnieniami root w REST API Cisco Prime Infrastructure i EPNM

CVE-2018-15379CRITICAL9.8PL ✓ten sam produkt

Cisco Prime Infrastructure — nieautoryzowany upload pliku przez TFTP (RCE)

CVE-2018-0258CRITICAL9.8PL ✓ten sam produkt

Cisco Prime — path traversal i zdalne wykonanie kodu przez upload pliku

CVE-2016-1289CRITICAL9.8PL ✓ten sam produkt

RCE i ujawnienie danych w API Cisco Prime Infrastructure i EPNM

CVE-2016-1291CRITICAL9.8PL ✓ten sam produkt

RCE przez deserializację w Cisco Prime Infrastructure i EPNM