CVE-2016-1360
Summary
| CVE | CVE-2016-1360 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-03-12 02:59:03 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390. |
Risk And Classification
Primary CVSS: v3.0 7.1 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-200 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.1 | HIGH | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| 2.0 | [email protected] | Primary | 3 | AV:L/AC:M/Au:S/C:P/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:M/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Prime Lan Management Solution | 4.1_base | All | All | All |
| Application | Cisco | Prime Lan Management Solution | 4.2.1 | All | All | All |
| Application | Cisco | Prime Lan Management Solution | 4.2.2 | All | All | All |
| Application | Cisco | Prime Lan Management Solution | 4.2.3 | All | All | All |
| Application | Cisco | Prime Lan Management Solution | 4.2.4 | All | All | All |
| Application | Cisco | Prime Lan Management Solution | 4.2.5 | All | All | All |
| Application | Cisco | Prime Lan Management Solution | 4.2_base | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Prime LAN Management Solution Default Decryption Key Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Vendor Advisory |
| Cisco Prime LAN Management Solution Flaw Lets Local Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.