QID 730721
Date Published: 2023-03-08
QID 730721: Cisco Evolved Programmable Network Manager Improper Input Validation Vulnerbility
The Cisco Evolved Programmable Network Manager (EPNM) is designed to provide simplified, converged, end-to-end lifecycle management for carrier-grade networks.
Affected Versions:
Cisco Evolved Programmable Network Manager v1.2.0.0
QID Detection Logic (Unauthenticated):
The QID sends a GET request to endpoint 'webacs/pages/common/login.jsp' to read the version banner.
The vulnerability allows remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request.
Solution
The vendor has issued a fix for these vulnerabilities. Please refer to the vendor advisory CVE-2016-1291 which addresses this issue.
Vendor References
CVEs related to QID 730721
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2016-1291 |
|