First published: Sat Jul 02 2016(Updated: )
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Infrastructure | =1.2 | |
Cisco Prime Infrastructure | =1.2.0.103 | |
Cisco Prime Infrastructure | =1.2.1 | |
Cisco Prime Infrastructure | =1.3 | |
Cisco Prime Infrastructure | =1.3.0.20 | |
Cisco Prime Infrastructure | =1.4 | |
Cisco Prime Infrastructure | =1.4.0.45 | |
Cisco Prime Infrastructure | =1.4.1 | |
Cisco Prime Infrastructure | =1.4.2 | |
Cisco Prime Infrastructure | =2.0 | |
Cisco Prime Infrastructure | =2.1.0 | |
Cisco Prime Infrastructure | =2.2 | |
Cisco Prime Infrastructure | =2.2\(2\) | |
Cisco Prime Infrastructure | =3.0 | |
Cisco Prime Infrastructure | =3.1 | |
Cisco Evolved Programmable Network Manager | =1.2.0 | |
Cisco Evolved Programmable Network Manager | =1.2.1.3 | |
Cisco Evolved Programmable Network Manager | =1.2.200 | |
Cisco Evolved Programmable Network Manager | =1.2.300 | |
Cisco Evolved Programmable Network Manager | =1.2.400 | |
Cisco Evolved Programmable Network Manager | =1.2.500 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1408 allows remote authenticated users to execute arbitrary commands or upload files through crafted HTTP requests.
CVE-2016-1408 affects Cisco Prime Infrastructure versions from 1.2 through 3.1.
Yes, Cisco Evolved Programmable Network Manager versions 1.2 and 2.0 are also affected by CVE-2016-1408.
Exploiting CVE-2016-1408 can allow unauthorized command execution and file uploads, potentially compromising system integrity.
To mitigate CVE-2016-1408, it is recommended to apply available patches or updates provided by Cisco for the affected software.