peter bassill · operator
$ cve CVE-2016-1416 JSON

CVE-2016-1416

9.8
CRITICAL · CVSS 3.0 · EPSS 4.5% (pctl 91)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administrator privileges via a crafted login attempt, aka Bug ID CSCuv37513.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.54% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploitnone known
Published2016-07-02
Last modified2026-06-17

Affected (1)

VendorProduct
ciscoprime collaboration provisioning

References

→ the Explorer  ·  watch your stack  ·  NVD