Vulnslist

find the latest Cisco vulnerabilities

Cisco Prime Network Analysis Module Unauthenticated Remote Code Execution Vulnerability

cisco-sa-20160601-prime · High · Published · Updated

A vulnerability in the web interface of Cisco Network Analysis Modules could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of the affected device with the privileges of the web server. The vulnerability is due to a failure to properly sanitize user input prior to executing an external command derived from the input. An attacker could exploit the vulnerability by submitting a crafted HTTP request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands or code on the underlying operating system with the reduced privileges of the web server. Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160601-prime

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2016-1388
Cisco Bug IDsCSCuy21882
CVSS ScoreBase 7.5
Base 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C
Product Names From Source
Cisco Prime Network Analysis Module Software, Cisco Prime Virtual Network Analysis Module

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2016-1388 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2016-1388 Cisco OpenVuln
Cisco Prime Virtual Network Analysis Module CVE-2016-1388 Cisco OpenVuln
Cisco Prime Network Analysis Module Software CVE-2016-1388 Cisco OpenVuln
Cisco Prime Network CVE-2016-1388 Cisco OpenVuln