Web API Privilege Escalation in Cisco Prime Infrastructure and Evolved Programmable Network Manager
CVE-2016-1290

8.1HIGH

Key Information:

Summary

A vulnerability exists in the web API of Cisco Prime Infrastructure and Evolved Programmable Network Manager that allows remote authenticated users to bypass intended role-based access control (RBAC) restrictions. This could enable unauthorized access to sensitive functions via crafted HTTP requests that do not conform to established pattern filters, posing significant risks to network management capabilities.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.