Web API Privilege Escalation in Cisco Prime Infrastructure and Evolved Programmable Network Manager
CVE-2016-1290
8.1HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 6 April 2016
Summary
A vulnerability exists in the web API of Cisco Prime Infrastructure and Evolved Programmable Network Manager that allows remote authenticated users to bypass intended role-based access control (RBAC) restrictions. This could enable unauthorized access to sensitive functions via crafted HTTP requests that do not conform to established pattern filters, posing significant risks to network management capabilities.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved