Vulnerability Details CVE-2016-1408
Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.0%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.5
Products affected by CVE-2016-1408
-
cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.0
-
cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.1.3
-
cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.200
-
cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.300
-
cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.400
-
cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.500
-
cpe:2.3:a:cisco:prime_infrastructure:1.2
-
cpe:2.3:a:cisco:prime_infrastructure:1.2.0.103
-
cpe:2.3:a:cisco:prime_infrastructure:1.2.1
-
cpe:2.3:a:cisco:prime_infrastructure:1.3
-
cpe:2.3:a:cisco:prime_infrastructure:1.3.0.20
-
cpe:2.3:a:cisco:prime_infrastructure:1.4
-
cpe:2.3:a:cisco:prime_infrastructure:1.4.0.45
-
cpe:2.3:a:cisco:prime_infrastructure:1.4.1
-
cpe:2.3:a:cisco:prime_infrastructure:1.4.2
-
cpe:2.3:a:cisco:prime_infrastructure:2.0
-
cpe:2.3:a:cisco:prime_infrastructure:2.1.0
-
cpe:2.3:a:cisco:prime_infrastructure:2.2
-
cpe:2.3:a:cisco:prime_infrastructure:2.2(2)
-
cpe:2.3:a:cisco:prime_infrastructure:3.0
-
cpe:2.3:a:cisco:prime_infrastructure:3.1