First published: Sun Feb 07 2016(Updated: )
The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Security Manager | =9.0.0 | |
Cisco Prime Security Manager | =9.0.1-40 | |
Cisco Prime Security Manager | =9.0.2-68 | |
Cisco Prime Security Manager | =9.1.0 | |
Cisco Prime Security Manager | =9.1.2-29 | |
Cisco Prime Security Manager | =9.1.2-42 | |
Cisco Prime Security Manager | =9.1.3-8 | |
Cisco Prime Security Manager | =9.1.3-10 | |
Cisco Prime Security Manager | =9.1.3-13 | |
Cisco Prime Security Manager | =9.2.0 | |
Cisco Prime Security Manager | =9.2.1-1 | |
Cisco Prime Security Manager | =9.2.1-2 | |
Cisco ASA CX Context-Aware Security | =9.0.1 | |
Cisco ASA CX Context-Aware Security | =9.0.1-40 | |
Cisco ASA CX Context-Aware Security | =9.0.2 | |
Cisco ASA CX Context-Aware Security | =9.0.2-68 | |
Cisco ASA CX Context-Aware Security | =9.0_base | |
Cisco ASA CX Context-Aware Security | =9.1.2-29 | |
Cisco ASA CX Context-Aware Security | =9.1.2-42 | |
Cisco ASA CX Context-Aware Security | =9.1.3-8 | |
Cisco ASA CX Context-Aware Security | =9.1.3-10 | |
Cisco ASA CX Context-Aware Security | =9.1.3-13 | |
Cisco ASA CX Context-Aware Security | =9.2.1-1 | |
Cisco ASA CX Context-Aware Security | =9.2.1-2 | |
Cisco ASA CX Context-Aware Security | =9.2.1-3 | |
Cisco ASA CX Context-Aware Security | =9.2.1-4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1301 has a medium severity rating due to its potential impact on the integrity of the system.
To fix CVE-2016-1301, upgrade the affected Cisco software to version 9.3.1.1(112) or later.
CVE-2016-1301 affects users of Cisco ASA-CX Content-Aware Security software prior to version 9.3.1.1(112) and Cisco Prime Security Manager versions before 9.3.1.1(112).
The impact of CVE-2016-1301 allows remote authenticated users to change arbitrary passwords via crafted HTTP requests.
There is no official workaround for CVE-2016-1301; the best mitigation is to update the software to the patched version.