Beveiligingsadvies

CVE-2016-1406

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2016-05-25 01:00:00
Laatst bijgewerkt 2024-08-05 22:55:14
Toegewezen door cisco
CVSS-score geen score
Status PUBLISHED

Beschrijving

The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.