CVE-2016-1408: Input Validation
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
Affected Software
Event History
Frequently Asked Questions
What are the vulnerabilities associated with CVE-2016-1408?
CVE-2016-1408 allows remote authenticated users to execute arbitrary commands or upload files through crafted HTTP requests.
What versions of Cisco Prime Infrastructure are affected by CVE-2016-1408?
CVE-2016-1408 affects Cisco Prime Infrastructure versions from 1.2 through 3.1.
Is Cisco Evolved Programmable Network Manager affected by CVE-2016-1408?
Yes, Cisco Evolved Programmable Network Manager versions 1.2 and 2.0 are also affected by CVE-2016-1408.
What is the potential impact of exploiting CVE-2016-1408?
Exploiting CVE-2016-1408 can allow unauthorized command execution and file uploads, potentially compromising system integrity.
How can I mitigate the risks associated with CVE-2016-1408?
To mitigate CVE-2016-1408, it is recommended to apply available patches or updates provided by Cisco for the affected software.