CVE-2016-1291
9.8
CRITICAL · CVSS 3.0 · EPSS 6.8% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.77% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-04-06 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| cisco | evolved programmable network manager |
| cisco | prime infrastructure |
| sun | opensolaris |
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcode
- http://www.securitytracker.com/id/1035497
- https://blogs.securiteam.com/index.php/archives/2727
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcode
- http://www.securitytracker.com/id/1035497
- https://blogs.securiteam.com/index.php/archives/2727
→ the Explorer · watch your stack · NVD