CVE-2016-1408: Cisco Evolved Programmable Network Manager

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

Cisco Prime Infrastructure 1.2 through 3.1 and Evolved Programmable Network Manager (EPNM) 1.2 and 2.0 allow remote authenticated users to execute arbitrary commands or upload files via a crafted HTTP request, aka Bug ID CSCuz01488.

Affected products

  • Cisco Evolved Programmable Network Manager: version 1.2.0 only; version 1.2.1.3 only; version 1.2.200 only; version 1.2.300 only; version 1.2.400 only; version 1.2.500 only
  • Cisco Prime Infrastructure: version 1.2 only; version 1.2.0.103 only; version 1.2.1 only; version 1.3 only; version 1.3.0.20 only; version 1.4 only; …

Published 2016-07-02. Last modified 2026-06-17.