CVE-2016-1391
high
CVSS v3
8.8
CVSS v2
6.5
VIR risk
8.8
Description
Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) allow remote authenticated users to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuy21889.
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160601-prime2
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | prime_network_analysis_module_software | 5.0.0 | |
| cisco | prime_network_analysis_module_software | 5.0.1 | |
| cisco | prime_network_analysis_module_software | 5.0.2 | |
| cisco | prime_network_analysis_module_software | 5.1.0 | |
| cisco | prime_network_analysis_module_software | 5.1.2 | |
| cisco | prime_network_analysis_module_software | 6.0.2 | |
| cisco | prime_network_analysis_module_software | 6.1.0 | |
| cisco | prime_network_analysis_module_software | 6.1.1 | |
| cisco | prime_network_analysis_module_software | 6.2.0 | |
| cisco | prime_virtual_network_analysis_module_software | 6.0.0 | |
| cisco | prime_virtual_network_analysis_module_software | 6.1.0 | |
| cisco | prime_virtual_network_analysis_module_software | 6.2.0 | |
| cisco | prime_virtual_network_analysis_module_software | 6.2.1 | |
References
CWEs
CWE-20
Verify integrity in audit chain (admin only). AS-IS.