CVE-2016-1320: OS Command Injection
Published Feb 12, 2016
·Updated
The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.
Affected Software
3 affected components
Cisco Prime Collaboration=9.0.0
Cisco Prime Collaboration=9.0.5
Cisco Prime Collaboration=11.0.0
Event History
Feb 12, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1320?
CVE-2016-1320 has been assigned a Medium severity rating due to the potential for unauthorized command execution.
2
Which versions of Cisco Prime Collaboration are affected by CVE-2016-1320?
CVE-2016-1320 affects Cisco Prime Collaboration versions 9.0.0, 9.0.5, and 11.0.0.
3
How do I fix CVE-2016-1320?
To fix CVE-2016-1320, you should apply the appropriate security patch released by Cisco for the affected versions.
4
Can local users exploit CVE-2016-1320?
Yes, local users with administrator privileges can exploit CVE-2016-1320 to execute arbitrary OS commands as root.
5
What impact does CVE-2016-1320 have on system security?
CVE-2016-1320 can compromise system security by allowing unauthorized execution of commands, potentially leading to a full system compromise.