CVE-2016-1291
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 6.77% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- cisco/evolved programmable network manager · cisco/prime infrastructure · sun/opensolaris
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcodeVendor Advisory
- http://www.securitytracker.com/id/1035497
- https://blogs.securiteam.com/index.php/archives/2727Third Party Advisory, VDB Entry
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcodeVendor Advisory
- http://www.securitytracker.com/id/1035497
- https://blogs.securiteam.com/index.php/archives/2727Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.