8.5
CVSSv2

CVE-2016-1301

Published: 07/02/2016 Updated: 06/12/2016
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 756
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

The RBAC implementation in Cisco ASA-CX Content-Aware Security software prior to 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software prior to 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco asa cx context-aware security software 9.1.3-10

cisco asa cx context-aware security software 9.1.2-42

cisco asa cx context-aware security software 9.1.2-29

cisco prime security manager 9.0.1-40

cisco prime security manager 9.0.2-68

cisco prime security manager 9.1.3-13

cisco prime security manager 9.2.1-1

cisco asa cx context-aware security software 9.1.3-8

cisco asa cx context-aware security software 9.1.3-13

cisco asa cx context-aware security software 9.0.1

cisco prime security manager 9.0.0

cisco prime security manager 9.1.3-8

cisco prime security manager 9.1.3-10

cisco asa cx context-aware security software 9.2.1-4

cisco asa cx context-aware security software 9.2.1-3

cisco asa cx context-aware security software 9.0_base

cisco asa cx context-aware security software 9.0.2-68

cisco prime security manager 9.1.0

cisco prime security manager 9.2.0

cisco prime security manager 9.2.1-2

cisco asa cx context-aware security software 9.2.1-2

cisco asa cx context-aware security software 9.2.1-1

cisco asa cx context-aware security software 9.0.2

cisco asa cx context-aware security software 9.0.1-40

cisco prime security manager 9.1.2-29

cisco prime security manager 9.1.2-42

Vendor Advisories

A vulnerability in the role-based access control of Cisco ASA-CX and Cisco Prime Security Manager (PRSM) could allow an authenticated, remote attacker to change the password of any user on the system The vulnerability exists because the password change request is not fully qualified An authenticated attacker with a user role other than Administr ...