CVE-2016-1301 - Improper Access Control

Severity

85%

Complexity

68%

Confidentiality

165%

The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.

The RBAC implementation in Cisco ASA-CX Content-Aware Security software before 9.3.1.1(112) and Cisco Prime Security Manager (PRSM) software before 9.3.1.1(112) allows remote authenticated users to change arbitrary passwords via a crafted HTTP request, aka Bug ID CSCuo94842.

CVSS 3.0 Base Score 8.8. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

CVSS 2.0 Base Score 8.5. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:S/C:C/I:C/A:C).

Overview

Type

Cisco

First reported 9 years ago

2016-02-07 11:59:00

Last updated 8 years ago

2016-12-06 03:06:00

Affected Software

Cisco Prime Security Manager 9.0.0

9.0.0

Cisco Prime Security Manager 9.0.1-40

9.0.1-40

Cisco Prime Security Manager 9.0.2-68

9.0.2-68

Cisco Prime Security Manager 9.1.0

9.1.0

Cisco Prime Security Manager (aka PRSM) 9.1.2-29

9.1.2-29

Cisco Prime Security Manager (aka PRSM) 9.1.2-42

9.1.2-42

Cisco Prime Security Manager (aka PRSM) 9.1.3-8

9.1.3-8

Cisco Prime Security Manager (aka PRSM) 9.1.3-10

9.1.3-10

Cisco Prime Security Manager (aka PRSM) 9.1.3-13

9.1.3-13

Cisco Prime Security Manager 9.2.0

9.2.0

Cisco Prime Security Manager (aka PRSM) 9.2.1-1

9.2.1-1

Cisco Prime Security Manager (aka PRSM) 9.2.1-2

9.2.1-2

Cisco ASA CX Context-Aware Security Software 9.0.1

9.0.1

Cisco ASA CX Context-Aware Security Software 9.0.1-40

9.0.1-40

Cisco ASA CX Context-Aware Security Software 9.0.2

9.0.2

Cisco ASA CX Context-Aware Security Software 9.0.2-68

9.0.2-68

Cisco ASA CX Context-Aware Security Software 9.0 BASE

9.0_base

Cisco ASA CX Context-Aware Security Software 9.1.2-29

9.1.2-29

Cisco ASA CX Context-Aware Security Software 9.1.2-42

9.1.2-42

Cisco ASA CX Context-Aware Security Software 9.1.3-8

9.1.3-8

Cisco ASA CX Context-Aware Security Software 9.13.10

9.1.3-10

Cisco ASA CX Context-Aware Security Software 9.1.3-13

9.1.3-13

Cisco ASA CX Context-Aware Security Software 9.2.1-1

9.2.1-1

Cisco ASA CX Context-Aware Security Software 9.2.1-2

9.2.1-2

Cisco ASA CX Context-Aware Security Software 9.2.1-3

9.2.1-3

Cisco ASA CX Context-Aware Security Software 9.2.1-4

9.2.1-4

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.