peter bassill · operator
$ cve CVE-2016-1291 JSON

CVE-2016-1291

9.8
CRITICAL · CVSS 3.0 · EPSS 6.8% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.77% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2016-04-06
Last modified2026-06-17

Affected (3)

VendorProduct
ciscoevolved programmable network manager
ciscoprime infrastructure
sunopensolaris

References

→ the Explorer  ·  watch your stack  ·  NVD