First published: Thu Jul 07 2016(Updated: )
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Infrastructure | =3.0 | |
Cisco Prime Infrastructure | =3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1442 has a severity rating of high due to its potential for remote command execution.
The mitigation for CVE-2016-1442 involves upgrading Cisco Prime Infrastructure to version 3.1.1 or later.
CVE-2016-1442 affects remote authenticated users of Cisco Prime Infrastructure versions 3.0 and 3.1.
CVE-2016-1442 allows remote authenticated users to execute arbitrary commands, potentially compromising the system.
There have been reported cases of CVE-2016-1442 being exploited in the wild, increasing the urgency for remediation.