CVE-2016-1291

EUVD-2016-2390
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
ciscoevolved_programmable_network_manager
1.2.0
ciscoprime_infrastructure
1.2
ciscoprime_infrastructure
1.2.0.103
ciscoprime_infrastructure
1.2.1
ciscoprime_infrastructure
1.3
ciscoprime_infrastructure
1.3.0.20
ciscoprime_infrastructure
1.4
ciscoprime_infrastructure
1.4.0.45
ciscoprime_infrastructure
1.4.1
ciscoprime_infrastructure
1.4.2
ciscoprime_infrastructure
2.0
ciscoprime_infrastructure
2.1.0
ciscoprime_infrastructure
2.2
𝑥
= Vulnerable software versions