CVE-2016-1290 describes a privilege escalation vulnerability in the web API of Cisco Prime Infrastructure versions 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2. A remote authenticated attacker can bypass Role-Based Access Control (RBAC) restrictions and gain elevated privileges by crafting an HTTP request that circumvents a pattern filter. This vulnerability carries a CVSSv3 score of 8.1 (HIGH), indicating a network-based attack with low attack complexity, requiring only low privileges, and resulting in high impact to confidentiality and integrity. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, though it received limited media coverage at the time of disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.0CPE matchmatch criteria | cpe:2.3:a:cisco:evolved_programmable_network_manager:1.2.0:*:*:*:*:*:*:* | ||
1.2CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:1.2:*:*:*:*:*:*:* | ||
1.2.0.103CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:1.2.0.103:*:*:*:*:*:*:* | ||
1.2.1CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:1.2.1:*:*:*:*:*:*:* | ||
1.3CPE matchmatch criteria | cpe:2.3:a:cisco:prime_infrastructure:1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.