CVE-2016-6443: Cisco Evolved Programmable Network Manager

High severity, CVSS 8.8. EPSS: 3% chance of exploitation in the next 30 days.

A vulnerability in the Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL database interface could allow an authenticated, remote attacker to impact system confidentiality by executing a subset of arbitrary SQL queries that can cause product instability. More Information: CSCva27038, CSCva28335. Known Affected Releases: 3.1(0.128), 1.2(400), 2.0(1.0.34A).

Affected products

  • Cisco Evolved Programmable Network Manager: version 1.2 only; version 2.0 only
  • Cisco Prime Infrastructure: version 1.2 only; version 1.2.0.103 only; version 1.2.1 only; version 1.3 only; version 1.3.0.20 only; version 1.4 only; …

Published 2016-10-27. Last modified 2026-06-17.