CVE-2016-1291

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.2.0.103:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.3.0.20:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.4.0.45:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:2.2:*:*:*:*:*:*:*
cpe:2.3:o:sun:opensolaris:snv_124:*:sparc:*:*:*:*:*

History

21 Nov 2024, 02:46

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcode - Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcode - Vendor Advisory
References () http://www.securitytracker.com/id/1035497 - () http://www.securitytracker.com/id/1035497 -
References () https://blogs.securiteam.com/index.php/archives/2727 - Third Party Advisory, VDB Entry () https://blogs.securiteam.com/index.php/archives/2727 - Third Party Advisory, VDB Entry

Information

Published : 2016-04-06 23:59

Updated : 2024-11-21 02:46


NVD link : CVE-2016-1291

Mitre link : CVE-2016-1291

CVE.ORG link : CVE-2016-1291


JSON object : View

Products Affected

cisco

  • prime_infrastructure
  • evolved_programmable_network_manager

sun

  • opensolaris
CWE
CWE-20

Improper Input Validation