CVE-2016-1406: High severity cisco evolved programmable network manager vulnerability
The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1406?
CVE-2016-1406 has a severity rating of high due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2016-1406?
To fix CVE-2016-1406, upgrade to a version of Cisco Prime Infrastructure or Cisco Evolved Programmable Network Manager that is not affected by this vulnerability.
Who is affected by CVE-2016-1406?
CVE-2016-1406 affects users of Cisco Prime Infrastructure before version 3.1 and Cisco Evolved Programmable Network Manager before version 1.2.4.
What type of attack does CVE-2016-1406 enable?
CVE-2016-1406 enables remote authenticated users to bypass role-based access control restrictions via crafted JSON data.
Is there a workaround for CVE-2016-1406?
There is no documented workaround for CVE-2016-1406; the recommended action is to upgrade the impacted software.