3
CVSSv2

CVE-2016-1360

Published: 12/03/2016 Updated: 03/12/2016
CVSS v2 Base Score: 3 | Impact Score: 4.9 | Exploitability Score: 2.7
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 267
Vector: AV:L/AC:M/Au:S/C:P/I:P/A:N

Vulnerability Summary

Cisco Prime LAN Management Solution (LMS) up to and including 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime lan management solution 4.2.1

cisco prime lan management solution 4.2_base

cisco prime lan management solution 4.2.3

cisco prime lan management solution 4.2.2

cisco prime lan management solution 4.2.5

cisco prime lan management solution 4.2.4

cisco prime lan management solution 4.1_base

Vendor Advisories

A vulnerability in Cisco Prime LAN Management Solution (LMS) could allow an authenticated, local attacker to decrypt and access data fields in LMS databases that are used to manage devices in Cisco networks The vulnerability is due to the presence of a default database decryption key that is shared across installations of Cisco Prime LMS An auth ...