CVE-2016-1290
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.49%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 1.49% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- cisco/evolved programmable network manager · cisco/prime infrastructure · sun/opensolaris
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-privauthVendor Advisory
- http://www.securitytracker.com/id/1035498
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-privauthVendor Advisory
- http://www.securitytracker.com/id/1035498
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.