First published: Sat Mar 12 2016(Updated: )
Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime LAN Management Solution | =4.1_base | |
Cisco Prime LAN Management Solution | =4.2.1 | |
Cisco Prime LAN Management Solution | =4.2.2 | |
Cisco Prime LAN Management Solution | =4.2.3 | |
Cisco Prime LAN Management Solution | =4.2.4 | |
Cisco Prime LAN Management Solution | =4.2.5 | |
Cisco Prime LAN Management Solution | =4.2_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1360 is considered a high severity vulnerability due to its potential to expose sensitive data.
To fix CVE-2016-1360, upgrade Cisco Prime LAN Management Solution to version 4.2.6 or later.
CVE-2016-1360 affects Cisco Prime LAN Management Solution versions 4.1_base through 4.2.5.
CVE-2016-1360 allows local users to access cleartext data stored in the database.
There is no official workaround for CVE-2016-1360; upgrading to a fixed version is recommended.