RULE(RULE ID:312936)

Rule General Information
Release Date: 2017-11-28
Rule Name: MISC Cisco Prime Infrastructure and EPNM Deserialization Code Execution Vulnerability - 2 (CVE-2016-1291)
Severity:
CVE ID:
Rule Protection Details
Description: Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcode
SecurityTrackerID:1035497
https://blogs.securiteam.com/index.php/archives/2727
Solutions
\tCisco has released advisories on its website. Please visit the following website for more information:
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160406-remcode