QID 730721

Date Published: 2023-03-08

QID 730721: Cisco Evolved Programmable Network Manager Improper Input Validation Vulnerbility

The Cisco Evolved Programmable Network Manager (EPNM) is designed to provide simplified, converged, end-to-end lifecycle management for carrier-grade networks.

Affected Versions:
Cisco Evolved Programmable Network Manager v1.2.0.0

QID Detection Logic (Unauthenticated):
The QID sends a GET request to endpoint 'webacs/pages/common/login.jsp' to read the version banner.

The vulnerability allows remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    The vendor has issued a fix for these vulnerabilities. Please refer to the vendor advisory CVE-2016-1291 which addresses this issue.

    CVEs related to QID 730721

    Software Advisories
    Advisory ID Software Component Link
    CVE-2016-1291 URL Logo sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcode