Vulnslist

find the latest Cisco vulnerabilities

Cisco Prime Infrastructure XML External Entity Denial of Service Vulnerability

cisco-sa-20160302-cpi · Medium · Published · Updated

A vulnerability in the web-based user interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to have read access to confidential information stored in the affected system. In addition, the attacker could cause a partial denial of service (DoS) condition due to manipulation of system resources. The vulnerability is due to improper handling of XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by convincing the authenticated administrator of the affected system to import a crafted XML file. An exploit could allow the attacker to view confidential files or cause a DoS condition. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-cpi

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-1358
Cisco Bug IDsCSCuw81497
CVSS ScoreBase 5.5
Base 5.5 AV:N/AC:L/Au:S/C:P/I:N/A:P/E:F/RL:U/RC:C
Product Names From Source
Cisco Prime Infrastructure

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2016-1358 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2016-1358 Cisco OpenVuln
Cisco Application Centric Infrastructure Virtual Edge CVE-2016-1358 Cisco OpenVuln
Cisco Prime Infrastructure CVE-2016-1358 Cisco OpenVuln