490
VMScore

CVE-2016-1358

Published: 03/03/2016 Updated: 29/07/2019
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.4 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:P

Vulnerability Summary

A vulnerability in the web-based user interface of Cisco Prime Infrastructure could allow an authenticated, remote malicious user to have read access to confidential information stored in the affected system. In addition, the attacker could cause a partial denial of service (DoS) condition due to manipulation of system resources. The vulnerability is due to improper handling of XML External Entity (XXE) when parsing an XML file. An attacker could exploit this vulnerability by convincing the authenticated administrator of the affected system to import a crafted XML file. An exploit could allow the malicious user to view confidential files or cause a DoS condition. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-cpi

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime infrastructure 3.0

cisco prime infrastructure 2.2

cisco prime infrastructure 3.1

Vendor Advisories

A vulnerability in the web-based user interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to have read access to confidential information stored in the affected system In addition, the attacker could cause a partial denial of service (DoS) condition due to manipulation of system resources The vulnerability is du ...