CVE-2016-1290

high Cisco
CVSS v3 Base Score
8.1
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.2%
Exploitation probability in 30 days
Top 63% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
High
Integrity
High
Availability
None
Published: April 6, 2016 (3689 days ago)
Last Modified: May 6, 2026
Vendor: Cisco
Source: NVD

Description

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated users to bypass intended RBAC restrictions and gain privileges via an HTTP request that is inconsistent with a pattern filter, aka Bug ID CSCuy10227.

CWE

CWE-264

Affected Products

cisco evolved programmable network managercisco prime infrastructuresun opensolaris

References