Arbitrary Code Execution and Information Disclosure Vulnerability in Cisco Prime Infrastructure and EPNM (CSCuy10231)

Arbitrary Code Execution and Information Disclosure Vulnerability in Cisco Prime Infrastructure and EPNM (CSCuy10231)

CVE-2016-1289 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering managed-device credentials, aka Bug ID CSCuy10231.

Learn more about our Cis Benchmark Audit For Cisco.