CVE-2016-1388

Description

Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) allow remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuy21882.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.389

Associated Vulnerability

VulnerabilityOS Platform
Cisco Prime Network Analysis Module Unauthenticated Remote Code Execution Vulnerability For Cisco Prime Network Analysis Module SoftwareNCM
Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability (CVE-2016-1388)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706008Security Update for Cisco Prime Network Analysis Module Software 6.2(3)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234