The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: cisco

Published: 2016-05-25T01:00:00

Updated: 2016-11-29T16:57:01

Reserved: 2016-01-04T00:00:00


Link: CVE-2016-1406

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2016-05-25T01:59:09.757

Modified: 2019-07-29T17:47:15.557


Link: CVE-2016-1406

JSON object: View

cve-icon Redhat Information

No data.

CWE