CVE-2016-1291

Description

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.322

Associated Vulnerability

VulnerabilityOS Platform
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability For Cisco Prime InfrastructureNCM
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerability For Cisco Evolved Programmable Network ManagerNCM
Improper Input Validation Vulnerability (CVE-2016-1291)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705595Security Update for Cisco Prime Infrastructure 2.2(2)
PATCH-1705983Security Update for Cisco Evolved Programmable Network Manager 2.0(2.0.40)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234