Privilege Escalation Vulnerability in Cisco Prime Infrastructure and Evolved Programmable Network Manager
CVE-2016-1406
8.8HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 25 May 2016
Summary
The API web interface in specific versions of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager exhibits a vulnerability that allows remote authenticated users to circumvent role-based access control (RBAC) mechanisms. By exploiting crafted JSON data, unauthorized access to sensitive information can be achieved, resulting in potential privilege escalation. This flaw underscores the critical need for rigorous security practices and timely updates to safeguard sensitive data.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved