CVE-2016-1360: Infoleak
Published Mar 12, 2016
·Updated
Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390.
Affected Software
7 affected components
cisco Prime LAN Management Solution=4.1_base
cisco Prime LAN Management Solution=4.2.1
cisco Prime LAN Management Solution=4.2.2
cisco Prime LAN Management Solution=4.2.3
cisco Prime LAN Management Solution=4.2.4
cisco Prime LAN Management Solution=4.2.5
cisco Prime LAN Management Solution=4.2_base
Event History
Mar 12, 2016
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1360?
CVE-2016-1360 is considered a high severity vulnerability due to its potential to expose sensitive data.
2
How do I fix CVE-2016-1360?
To fix CVE-2016-1360, upgrade Cisco Prime LAN Management Solution to version 4.2.6 or later.
3
What systems are affected by CVE-2016-1360?
CVE-2016-1360 affects Cisco Prime LAN Management Solution versions 4.1_base through 4.2.5.
4
What kind of data can be accessed through CVE-2016-1360?
CVE-2016-1360 allows local users to access cleartext data stored in the database.
5
Is there a workaround for CVE-2016-1360?
There is no official workaround for CVE-2016-1360; upgrading to a fixed version is recommended.