CVE-2016-1291: Cisco Evolved Programmable Network Manager

Critical severity, CVSS 9.8. EPSS: 6.8% chance of exploitation in the next 30 days.

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

Affected products

  • Cisco Evolved Programmable Network Manager: version 1.2.0 only
  • Cisco Prime Infrastructure: version 1.2 only; version 1.2.0.103 only; version 1.2.1 only; version 1.3 only; version 1.3.0.20 only; version 1.4 only; …
  • Sun Opensolaris: version snv_124 only

Published 2016-04-06. Last modified 2026-06-17.