ID

VAR-201606-0428


CVE

CVE-2016-1388


TITLE

Cisco Prime Network Analysis Module and Prime Virtual Network Analysis Module In any OS Command execution vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2016-002990

DESCRIPTION

Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) allow remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuy21882. Vendors have confirmed this vulnerability Bug ID CSCuy21882 It is released as. Supplementary information : CWE Vulnerability type by CWE-77: Improper Neutralization of Special Elements used in a Command ( Command injection ) Has been identified. http://cwe.mitre.org/data/definitions/77.htmlSkillfully crafted by a third party HTTP Any via request OS The command may be executed. Multiple Cisco Prime Products are prone to a remote code-execution vulnerability. An attacker can exploit this issue to execute arbitrary code on the affected system. This may aid in further attacks. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP request to execute arbitrary commands in the underlying operating system of the affected device with Web server privileges

Trust: 1.98

sources: NVD: CVE-2016-1388 // JVNDB: JVNDB-2016-002990 // BID: 90985 // VULHUB: VHN-90207

AFFECTED PRODUCTS

vendor:ciscomodel:prime virtual network analysis module softwarescope:eqversion:6.1.0

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:6.0.2

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:5.0.0

Trust: 1.0

vendor:ciscomodel:network analysis modulescope:eqversion:*

Trust: 1.0

vendor:ciscomodel:prime virtual network analysis module softwarescope:eqversion:6.2.0

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:6.1.0

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:6.1.1

Trust: 1.0

vendor:ciscomodel:prime virtual network analysis module softwarescope:eqversion:6.0.0

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:5.1.0

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:5.0.2

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:6.2.0

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:5.1.2

Trust: 1.0

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:5.0.1

Trust: 1.0

vendor:ciscomodel:prime virtual network analysis module softwarescope:eqversion:6.2(1)

Trust: 0.8

vendor:ciscomodel:prime virtual network analysis module softwarescope:ltversion:6.2.x

Trust: 0.8

vendor:ciscomodel:prime network analysis module softwarescope:eqversion:6.2(1)

Trust: 0.8

vendor:ciscomodel:prime network analysis module softwarescope:ltversion:6.2.x

Trust: 0.8

vendor:ciscomodel:network analysis modulescope: - version: -

Trust: 0.6

sources: JVNDB: JVNDB-2016-002990 // CNNVD: CNNVD-201606-008 // NVD: CVE-2016-1388

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-1388
value: CRITICAL

Trust: 1.0

NVD: CVE-2016-1388
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201606-008
value: HIGH

Trust: 0.6

VULHUB: VHN-90207
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-1388
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-90207
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-1388
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-90207 // JVNDB: JVNDB-2016-002990 // CNNVD: CNNVD-201606-008 // NVD: CVE-2016-1388

PROBLEMTYPE DATA

problemtype:CWE-77

Trust: 1.1

problemtype:CWE-Other

Trust: 0.8

sources: VULHUB: VHN-90207 // JVNDB: JVNDB-2016-002990 // NVD: CVE-2016-1388

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201606-008

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201606-008

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-002990

PATCH

title:cisco-sa-20160601-primeurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160601-prime

Trust: 0.8

title:Cisco Prime Network Analysis Module and Cisco Prime Virtual Network Analysis Module Fixes for arbitrary command execution vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=62034

Trust: 0.6

sources: JVNDB: JVNDB-2016-002990 // CNNVD: CNNVD-201606-008

EXTERNAL IDS

db:NVDid:CVE-2016-1388

Trust: 2.8

db:SECTRACKid:1036013

Trust: 1.1

db:JVNDBid:JVNDB-2016-002990

Trust: 0.8

db:CNNVDid:CNNVD-201606-008

Trust: 0.7

db:BIDid:90985

Trust: 0.4

db:VULHUBid:VHN-90207

Trust: 0.1

sources: VULHUB: VHN-90207 // BID: 90985 // JVNDB: JVNDB-2016-002990 // CNNVD: CNNVD-201606-008 // NVD: CVE-2016-1388

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20160601-prime

Trust: 1.1

url:http://www.securitytracker.com/id/1036013

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-1388

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-1388

Trust: 0.8

url:http://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20160601-prime/

Trust: 0.6

sources: VULHUB: VHN-90207 // JVNDB: JVNDB-2016-002990 // CNNVD: CNNVD-201606-008 // NVD: CVE-2016-1388

CREDITS

Daniel Jensen from Security-Assessment.com

Trust: 0.6

sources: CNNVD: CNNVD-201606-008

SOURCES

db:VULHUBid:VHN-90207
db:BIDid:90985
db:JVNDBid:JVNDB-2016-002990
db:CNNVDid:CNNVD-201606-008
db:NVDid:CVE-2016-1388

LAST UPDATE DATE

2024-11-23T22:59:28.972000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-90207date:2016-11-30T00:00:00
db:BIDid:90985date:2016-06-01T00:00:00
db:JVNDBid:JVNDB-2016-002990date:2016-06-06T00:00:00
db:CNNVDid:CNNVD-201606-008date:2016-06-03T00:00:00
db:NVDid:CVE-2016-1388date:2024-11-21T02:46:21.007

SOURCES RELEASE DATE

db:VULHUBid:VHN-90207date:2016-06-03T00:00:00
db:BIDid:90985date:2016-06-01T00:00:00
db:JVNDBid:JVNDB-2016-002990date:2016-06-06T00:00:00
db:CNNVDid:CNNVD-201606-008date:2016-06-02T00:00:00
db:NVDid:CVE-2016-1388date:2016-06-03T02:01:07.613