CVE-2016-1290

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cisco:prime_infrastructure:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:2.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.3.0.20:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:2.2\\\(2\\\):*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:2.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.4:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:2.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.2.0.103:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.4.0.45:*:*:*:*:*:*:*
cpe:2.3:a:cisco:prime_infrastructure:1.3:*:*:*:*:*:*:*

Information

Published : 2016-04-06 16:59

Updated : 2019-07-29 10:47


NVD link : CVE-2016-1290

Mitre link : CVE-2016-1290


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

Advertisement

dedicated server usa

Products Affected

cisco

  • prime_infrastructure
  • evolved_programmable_network_manager