PatchSiren cyber security CVE debrief
CVE-2016-6484 Infoblox CVE debrief
CVE-2016-6484 is a CRLF injection vulnerability in Infoblox Network Automation NetMRI. The issue is described as affecting NetMRI before 7.1.1 and allowing remote attackers to inject arbitrary HTTP headers and perform HTTP response splitting through the contentType parameter in a login request. The NVD record classifies it as CWE-93 and rates it CVSS 3.0 6.1 (Medium).
- Vendor
- Infoblox
- Product
- Netmri
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-23
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for Infoblox NetMRI deployments, especially systems exposing the login endpoint to untrusted networks or users who may access the affected page during normal workflows.
Technical summary
The supplied NVD data describes a CRLF injection issue in config/userAdmin/login.tdf, where the contentType parameter can be used to inject HTTP headers and split responses. The CVSS vector is AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network reachability, no privileges required, and a user interaction requirement. The NVD CPE data marks NetMRI versions up to 7.0.1 as vulnerable, while the textual description says the issue affects versions before 7.1.1; that version detail should be verified against vendor guidance before planning remediation.
Defensive priority
Medium priority. The issue is remotely reachable and can affect confidentiality and integrity, but it requires user interaction and is not listed as causing availability impact. Prioritize any internet-facing or broadly reachable NetMRI management instances.
Recommended defensive actions
- Upgrade Infoblox NetMRI to 7.1.1 or later, as stated in the CVE description.
- Confirm the exact vulnerable version range in your environment, since the NVD CPE data in the supplied corpus lists versions through 7.0.1 while the description says before 7.1.1.
- Restrict access to the NetMRI login interface to trusted administrative networks wherever possible.
- Review logs and proxy/WAF telemetry for unusual response headers or signs of response splitting attempts against the login action.
- Validate that any compensating controls, such as reverse proxies or header normalization, do not depend on unsanitized request parameters.
Evidence notes
Evidence in the supplied corpus includes the official NVD record, the CVE.org record link, and third-party advisories/DB entries cited by MITRE references. The vulnerability is mapped to CWE-93, and the NVD CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N with severity Medium. Publication date is 2017-01-23T21:59:02.003Z; the record was last modified on 2026-05-13T00:24:29.033Z. The supplied data also contains a version-range discrepancy between the narrative description ('before 7.1.1') and the CPE criteria (vulnerable through 7.0.1).
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6484 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6484
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6484 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6484
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.