CVE-2016-1289
9.8
CRITICAL · CVSS 3.0 · EPSS 6.2% (pctl 93)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The API in Cisco Prime Infrastructure 1.2 through 3.0 and Evolved Programmable Network Manager (EPNM) 1.2 allows remote attackers to execute arbitrary code or obtain sensitive management information via a crafted HTTP request, as demonstrated by discovering managed-device credentials, aka Bug ID CSCuy10231.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.15% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-07-02 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| cisco | evolved programmable network manager |
| cisco | prime infrastructure |
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160629-piauthbypass
- http://www.securityfocus.com/bid/91504
- http://www.securitytracker.com/id/1036195
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160629-piauthbypass
- http://www.securityfocus.com/bid/91504
- http://www.securitytracker.com/id/1036195
→ the Explorer · watch your stack · NVD