Lucene search

K
ciscoCiscoCISCO-SA-20160127-NTPD
HistoryJan 27, 2016 - 8:00 p.m.

Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: January 2016

2016-01-2720:00:00
tools.cisco.com
89

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

0.097 Low

EPSS

Percentile

94.8%

Multiple Cisco products incorporate a version of the Network Time Protocol daemon (ntpd) package. Versions of this package are affected by one or more vulnerabilities that could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition or modify the time being advertised by a device acting as a Network Time Protocol (NTP) server.

On January 19, 2016, NTP Consortium at Network Time Foundation released a security advisory detailing 12 issues regarding multiple DoS vulnerabilities, information disclosure vulnerabilities, and logic issues that may allow an attacker to shift a client’s time. The vulnerabilities covered in this document are as follows:

CVE-2015-7973: Network Time Protocol Replay Attack on Authenticated Broadcast Mode Vulnerability
CVE-2015-7974: Network Time Protocol Missing Trusted Key Check
CVE-2015-7975: Standard Network Time Protocol Query Program nextvar() Missing Length Check
CVE-2015-7976: Standard Network Time Protocol Query Program saveconfig Command Allows Dangerous Characters in Filenames
CVE-2015-7978: Network Time Protocol Daemon reslist NULL Pointer Deference Denial of Service Vulnerability
CVE-2015-7977: Network Time Protocol Stack Exhaustion Denial of Service
CVE-2015-7979: Network Time Protocol Off-Path Broadcast Mode Denial of Service
CVE-2015-8138: Network Time Protocol Zero Origin Timestamp Bypass
CVE-2015-8139: Network Time Protocol Information Disclosure of Origin Timestamp
CVE-2015-8140: Standard Network Time Protocol Query Program Replay Attack
CVE-2015-8158: Standard and Special Network Time Protocol Query Program Infinite loop
Additional details on each of the vulnerabilities are in the official security advisory from the NTP Consortium at Network Time Foundation at the following link: Security Notice [“http://nwtime.org/security-policy/”]

Cisco has released software updates that address these vulnerabilities.

Workarounds that address some of these vulnerabilities may be available. Available workarounds will be documented in the corresponding Cisco bug for each affected product.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160127-ntpd

Affected configurations

Vulners
Node
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscosecure_access_control_systemMatchany
OR
ciscounityMatchany
OR
ciscoiosMatchany
OR
ciscoemergency_responderMatchany
OR
ciscoios_xr_softwareMatchany
OR
cisconac_applianceMatchany
OR
ciscointrusion_prevention_systemMatchany
OR
ciscounified_presence_serverMatchany
OR
ciscoace_application_control_engine_module_a3Matchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscoservice_control_engineMatchany
OR
ciscounity_connectionMatchany
OR
ciscotelepresence_mx200Matchany
OR
cisconx_osMatch4.1
OR
cisconx_osMatch5.0
OR
cisconx_osMatch4.2
OR
cisconx_osMatch5.1
OR
cisconx_osMatch5.2
OR
cisconx_osMatch6.1
OR
cisconx_osMatch4.0\(0\)n1
OR
cisconx_osMatch4.0\(1a\)n1
OR
cisconx_osMatch4.0\(1a\)n2
OR
cisconx_osMatch4.1\(3\)n1
OR
cisconx_osMatch4.1\(3\)n2
OR
cisconx_osMatch4.2\(1\)n1
OR
cisconx_osMatch4.2\(1\)n2
OR
cisconx_osMatch5.0\(2\)n1
OR
cisconx_osMatch5.0\(2\)n2
OR
cisconx_osMatch5.0\(3\)n1
OR
cisconx_osMatch5.0\(3\)n2
OR
cisconx_osMatch5.0\(3\)u1
OR
cisconx_osMatch5.0\(3\)u2
OR
cisconx_osMatch5.0\(3\)u3
OR
cisconx_osMatch5.0\(3\)u4
OR
cisconx_osMatch5.0\(3\)u5
OR
cisconx_osMatch5.1\(3\)n1
OR
cisconx_osMatch5.1\(3\)n2
OR
cisconx_osMatch5.2\(1\)n1
OR
cisconx_osMatch6.0
OR
cisconx_osMatch6.0\(2\)n1
OR
cisconx_osMatch6.0\(2\)n2
OR
cisconx_osMatch6.0\(2\)u1
OR
cisconx_osMatch6.0\(2\)u2
OR
cisconx_osMatch6.0\(2\)u3
OR
cisconx_osMatch6.0\(2\)u4
OR
cisconx_osMatch6.0\(2\)u5
OR
cisconx_osMatch6.1\(2\)i2
OR
cisconx_osMatch6.1\(2\)i3
OR
cisconx_osMatch6.2
OR
cisconx_osMatch7.0\(0\)n1
OR
cisconx_osMatch7.0\(1\)n1
OR
cisconx_osMatch7.0\(2\)n1
OR
cisconx_osMatch7.0\(3\)n1
OR
ciscoace_4700_series_application_control_engine_applianceMatchany
OR
ciscounified_communications_managerMatchany
OR
ciscoapplication_networking_managerMatchany
OR
ciscounified_provisioning_managerMatchany
OR
ciscophysical_access_gatewayMatchany
OR
ciscocisco_iosMatch3.2sgxe
OR
ciscocisco_iosMatch3.7sxe
OR
ciscocisco_iosMatch3.3sgxe
OR
ciscocisco_iosMatch3.8sxe
OR
ciscocisco_iosMatch3.9sxe
OR
ciscocisco_iosMatch3.2sexe
OR
ciscocisco_iosMatch3.3sexe
OR
ciscocisco_iosMatch3.3xoxe
OR
ciscocisco_iosMatch3.4sgxe
OR
ciscocisco_iosMatch3.5exe
OR
ciscocisco_iosMatch3.10sxe
OR
ciscocisco_iosMatch3.11sxe
OR
ciscocisco_iosMatch3.12sxe
OR
ciscocisco_iosMatch3.13sxe
OR
ciscocisco_iosMatch3.6exe
OR
ciscocisco_iosMatch3.14sxe
OR
ciscocisco_iosMatch3.15sxe
OR
ciscocisco_iosMatch3.3sqxe
OR
ciscocisco_iosMatch3.4sqxe
OR
ciscocisco_iosMatch3.7exe
OR
ciscocisco_iosMatchanyxe
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
cisconetwork_analysis_module_softwareMatchany
OR
ciscoironport_encryption_applianceMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscotelepresence_mxp_softwareMatchany
OR
ciscoshow_and_shareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
OR
ciscotelepresence_video_communication_serverMatchany
OR
cisconexus_1000vMatchanynexus_1000v
OR
ciscotelepresence_managerMatchany
OR
ciscoasa_cx_context-aware_security_softwareMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoprime_lan_management_solutionMatchany
OR
ciscoprime_collaborationMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoconnected_grid_network_management_systemMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_node_for_mcsMatchany
OR
ciscounified_computing_system_central_softwareMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscotelepresence_tc_softwareMatchany
OR
ciscotelepresence_te_softwareMatchany
OR
ciscovirtualization_experience_client_6000_series_firmwareMatchany
OR
ciscofinesseMatchany
OR
ciscosocialminerMatchany
OR
ciscomediasenseMatchany
OR
ciscounified_sip_proxyMatchany
OR
ciscomedia_experience_engine_5600Matchany
OR
ciscoucs_directorMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscounified_intelligence_centerMatchany
OR
ciscoprime_service_catalogMatchany
OR
cisconexus_1000vMatchanynexus_1000v
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
ciscoexpresswayMatchany
OR
cisco300_series_managed_switchesMatchany
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscounified_computing_system_softwareMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscoprime_collaboration_deploymentMatchany
OR
ciscotelepresence_isdn_gw_3241Matchany
OR
ciscotelepresence_conductorMatchany
OR
ciscomodular_encoding_platform_d9036_softwareMatchany
OR
ciscofirepower_system_softwareMatchany
OR
ciscovideoscape_policy_resource_managerMatchany
OR
ciscoprime_collaboration_assuranceMatchany
OR
ciscovirtual_topology_systemMatchany
OR
cisconexus_3000Matchany
OR
ciscocisco_policy_suiteMatchany
OR
ciscohosted_collaboration_mediation_fulfillmentMatchany
OR
ciscocloud_services_platform_2100Matchany
OR
ciscoapplication_and_content_networking_system_softwareMatchany
OR
ciscosecure_access_control_systemMatchany
OR
ciscounityMatchany
OR
ciscoiosMatchany
OR
ciscoemergency_responderMatchany
OR
ciscoios_xr_softwareMatchany
OR
cisconac_applianceMatchany
OR
ciscointrusion_prevention_systemMatchany
OR
ciscounified_presence_serverMatchany
OR
ciscoace_application_control_engine_module_a3Matchany
OR
ciscowide_area_application_servicesMatchany
OR
ciscounified_contact_center_enterpriseMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscoservice_control_engineMatchany
OR
ciscounity_connectionMatchany
OR
ciscotelepresence_mx200Matchany
OR
cisconx_osMatch4.1\(2\)
OR
cisconx_osMatch4.1\(3\)
OR
cisconx_osMatch4.1\(4\)
OR
cisconx_osMatch4.1\(5\)
OR
cisconx_osMatch5.0\(2a\)
OR
cisconx_osMatch5.0\(3\)
OR
cisconx_osMatch5.0\(5\)
OR
cisconx_osMatch4.2\(2a\)
OR
cisconx_osMatch4.2\(3\)
OR
cisconx_osMatch4.2\(4\)
OR
cisconx_osMatch4.2\(6\)
OR
cisconx_osMatch4.2\(8\)
OR
cisconx_osMatch5.1\(1\)
OR
cisconx_osMatch5.1\(1a\)
OR
cisconx_osMatch5.1\(3\)
OR
cisconx_osMatch5.1\(4\)
OR
cisconx_osMatch5.1\(5\)
OR
cisconx_osMatch5.1\(6\)
OR
cisconx_osMatch5.2\(1\)
OR
cisconx_osMatch5.2\(3a\)
OR
cisconx_osMatch5.2\(4\)
OR
cisconx_osMatch5.2\(5\)
OR
cisconx_osMatch5.2\(7\)
OR
cisconx_osMatch5.2\(9\)
OR
cisconx_osMatch6.1\(1\)
OR
cisconx_osMatch6.1\(2\)
OR
cisconx_osMatch6.1\(3\)
OR
cisconx_osMatch6.1\(4\)
OR
cisconx_osMatch6.1\(4a\)
OR
cisconx_osMatch4.0\(0\)n1\(1a\)
OR
cisconx_osMatch4.0\(0\)n1\(2\)
OR
cisconx_osMatch4.0\(0\)n1\(2a\)
OR
cisconx_osMatch4.0\(1a\)n1\(1\)
OR
cisconx_osMatch4.0\(1a\)n1\(1a\)
OR
cisconx_osMatch4.0\(1a\)n2\(1\)
OR
cisconx_osMatch4.0\(1a\)n2\(1a\)
OR
cisconx_osMatch4.1\(3\)n1\(1\)
OR
cisconx_osMatch4.1\(3\)n1\(1a\)
OR
cisconx_osMatch4.1\(3\)n2\(1\)
OR
cisconx_osMatch4.1\(3\)n2\(1a\)
OR
cisconx_osMatch4.2\(1\)n1\(1\)
OR
cisconx_osMatch4.2\(1\)n2\(1\)
OR
cisconx_osMatch4.2\(1\)n2\(1a\)
OR
cisconx_osMatch5.0\(2\)n1\(1\)
OR
cisconx_osMatch5.0\(2\)n2\(1\)
OR
cisconx_osMatch5.0\(2\)n2\(1a\)
OR
cisconx_osMatch5.0\(3\)n1\(1c\)
OR
cisconx_osMatch5.0\(3\)n2\(1\)
OR
cisconx_osMatch5.0\(3\)n2\(2\)
OR
cisconx_osMatch5.0\(3\)n2\(2a\)
OR
cisconx_osMatch5.0\(3\)n2\(2b\)
OR
cisconx_osMatch5.0\(3\)u1\(1\)
OR
cisconx_osMatch5.0\(3\)u1\(1a\)
OR
cisconx_osMatch5.0\(3\)u1\(1b\)
OR
cisconx_osMatch5.0\(3\)u1\(1d\)
OR
cisconx_osMatch5.0\(3\)u1\(2\)
OR
cisconx_osMatch5.0\(3\)u1\(2a\)
OR
cisconx_osMatch5.0\(3\)u2\(1\)
OR
cisconx_osMatch5.0\(3\)u2\(2\)
OR
cisconx_osMatch5.0\(3\)u2\(2a\)
OR
cisconx_osMatch5.0\(3\)u2\(2b\)
OR
cisconx_osMatch5.0\(3\)u2\(2c\)
OR
cisconx_osMatch5.0\(3\)u2\(2d\)
OR
cisconx_osMatch5.0\(3\)u3\(1\)
OR
cisconx_osMatch5.0\(3\)u3\(2\)
OR
cisconx_osMatch5.0\(3\)u3\(2a\)
OR
cisconx_osMatch5.0\(3\)u3\(2b\)
OR
cisconx_osMatch5.0\(3\)u4\(1\)
OR
cisconx_osMatch5.0\(3\)u5\(1\)
OR
cisconx_osMatch5.0\(3\)u5\(1a\)
OR
cisconx_osMatch5.0\(3\)u5\(1b\)
OR
cisconx_osMatch5.0\(3\)u5\(1c\)
OR
cisconx_osMatch5.0\(3\)u5\(1d\)
OR
cisconx_osMatch5.0\(3\)u5\(1e\)
OR
cisconx_osMatch5.0\(3\)u5\(1f\)
OR
cisconx_osMatch5.0\(3\)u5\(1g\)
OR
cisconx_osMatch5.0\(3\)u5\(1h\)
OR
cisconx_osMatch5.1\(3\)n1\(1\)
OR
cisconx_osMatch5.1\(3\)n1\(1a\)
OR
cisconx_osMatch5.1\(3\)n2\(1\)
OR
cisconx_osMatch5.1\(3\)n2\(1a\)
OR
cisconx_osMatch5.1\(3\)n2\(1b\)
OR
cisconx_osMatch5.1\(3\)n2\(1c\)
OR
cisconx_osMatch5.2\(1\)n1\(1\)
OR
cisconx_osMatch5.2\(1\)n1\(1a\)
OR
cisconx_osMatch5.2\(1\)n1\(1b\)
OR
cisconx_osMatch5.2\(1\)n1\(2\)
OR
cisconx_osMatch5.2\(1\)n1\(2a\)
OR
cisconx_osMatch5.2\(1\)n1\(3\)
OR
cisconx_osMatch5.2\(1\)n1\(4\)
OR
cisconx_osMatch5.2\(1\)n1\(5\)
OR
cisconx_osMatch5.2\(1\)n1\(6\)
OR
cisconx_osMatch5.2\(1\)n1\(7\)
OR
cisconx_osMatch5.2\(1\)n1\(8a\)
OR
cisconx_osMatch5.2\(1\)n1\(8\)
OR
cisconx_osMatch6.0\(1\)
OR
cisconx_osMatch6.0\(2\)
OR
cisconx_osMatch6.0\(3\)
OR
cisconx_osMatch6.0\(4\)
OR
cisconx_osMatch6.0\(2\)n1\(1\)
OR
cisconx_osMatch6.0\(2\)n1\(2\)
OR
cisconx_osMatch6.0\(2\)n1\(2a\)
OR
cisconx_osMatch6.0\(2\)n2\(1\)
OR
cisconx_osMatch6.0\(2\)n2\(1b\)
OR
cisconx_osMatch6.0\(2\)n2\(2\)
OR
cisconx_osMatch6.0\(2\)n2\(3\)
OR
cisconx_osMatch6.0\(2\)n2\(4\)
OR
cisconx_osMatch6.0\(2\)n2\(5\)
OR
cisconx_osMatch6.0\(2\)u1\(1\)
OR
cisconx_osMatch6.0\(2\)u1\(2\)
OR
cisconx_osMatch6.0\(2\)u1\(1a\)
OR
cisconx_osMatch6.0\(2\)u1\(3\)
OR
cisconx_osMatch6.0\(2\)u1\(4\)
OR
cisconx_osMatch6.0\(2\)u2\(1\)
OR
cisconx_osMatch6.0\(2\)u2\(2\)
OR
cisconx_osMatch6.0\(2\)u2\(3\)
OR
cisconx_osMatch6.0\(2\)u2\(4\)
OR
cisconx_osMatch6.0\(2\)u2\(5\)
OR
cisconx_osMatch6.0\(2\)u2\(6\)
OR
cisconx_osMatch6.0\(2\)u3\(1\)
OR
cisconx_osMatch6.0\(2\)u3\(2\)
OR
cisconx_osMatch6.0\(2\)u3\(3\)
OR
cisconx_osMatch6.0\(2\)u3\(4\)
OR
cisconx_osMatch6.0\(2\)u3\(5\)
OR
cisconx_osMatch6.0\(2\)u4\(1\)
OR
cisconx_osMatch6.0\(2\)u4\(2\)
OR
cisconx_osMatch6.0\(2\)u4\(3\)
OR
cisconx_osMatch6.0\(2\)u5\(1\)
OR
cisconx_osMatch6.1\(2\)i2\(1\)
OR
cisconx_osMatch6.1\(2\)i2\(2\)
OR
cisconx_osMatch6.1\(2\)i2\(2a\)
OR
cisconx_osMatch6.1\(2\)i2\(3\)
OR
cisconx_osMatch6.1\(2\)i2\(2b\)
OR
cisconx_osMatch6.1\(2\)i3\(1\)
OR
cisconx_osMatch6.1\(2\)i3\(2\)
OR
cisconx_osMatch6.1\(2\)i3\(3\)
OR
cisconx_osMatch6.2\(2\)
OR
cisconx_osMatch6.2\(2a\)
OR
cisconx_osMatch6.2\(6\)
OR
cisconx_osMatch6.2\(6b\)
OR
cisconx_osMatch6.2\(8\)
OR
cisconx_osMatch6.2\(8a\)
OR
cisconx_osMatch6.2\(8b\)
OR
cisconx_osMatch6.2\(10\)
OR
cisconx_osMatch7.0\(0\)n1\(1\)
OR
cisconx_osMatch7.0\(1\)n1\(1\)
OR
cisconx_osMatch7.0\(2\)n1\(1\)
OR
cisconx_osMatch7.0\(3\)n1\(1\)
OR
ciscoace_4710Match4700_series_application_control_engine_appliances
OR
ciscounified_communications_managerMatchany
OR
ciscoapplication_networking_managerMatchany
OR
ciscounified_provisioning_managerMatchany
OR
ciscophysical_access_gatewayMatchany
OR
ciscocisco_iosMatch3.2.0sgxe
OR
ciscocisco_iosMatch3.2.1sgxe
OR
ciscocisco_iosMatch3.2.2sgxe
OR
ciscocisco_iosMatch3.2.3sgxe
OR
ciscocisco_iosMatch3.2.4sgxe
OR
ciscocisco_iosMatch3.2.5sgxe
OR
ciscocisco_iosMatch3.2.6sgxe
OR
ciscocisco_iosMatch3.2.7sgxe
OR
ciscocisco_iosMatch3.2.8sgxe
OR
ciscocisco_iosMatch3.2.9sgxe
OR
ciscocisco_iosMatch3.7.0sxe
OR
ciscocisco_iosMatch3.7.1sxe
OR
ciscocisco_iosMatch3.7.2sxe
OR
ciscocisco_iosMatch3.7.3sxe
OR
ciscocisco_iosMatch3.7.4sxe
OR
ciscocisco_iosMatch3.7.5sxe
OR
ciscocisco_iosMatch3.7.6sxe
OR
ciscocisco_iosMatch3.7.7sxe
OR
ciscocisco_iosMatch3.3.0sgxe
OR
ciscocisco_iosMatch3.3.2sgxe
OR
ciscocisco_iosMatch3.3.1sgxe
OR
ciscocisco_iosMatch3.8.0sxe
OR
ciscocisco_iosMatch3.8.1sxe
OR
ciscocisco_iosMatch3.8.2sxe
OR
ciscocisco_iosMatch3.9.1sxe
OR
ciscocisco_iosMatch3.9.0sxe
OR
ciscocisco_iosMatch3.9.2sxe
OR
ciscocisco_iosMatch3.2.0sexe
OR
ciscocisco_iosMatch3.2.1sexe
OR
ciscocisco_iosMatch3.2.2sexe
OR
ciscocisco_iosMatch3.2.3sexe
OR
ciscocisco_iosMatch3.3.0sexe
OR
ciscocisco_iosMatch3.3.1sexe
OR
ciscocisco_iosMatch3.3.2sexe
OR
ciscocisco_iosMatch3.3.3sexe
OR
ciscocisco_iosMatch3.3.4sexe
OR
ciscocisco_iosMatch3.3.5sexe
OR
ciscocisco_iosMatch3.3.0xoxe
OR
ciscocisco_iosMatch3.3.1xoxe
OR
ciscocisco_iosMatch3.3.2xoxe
OR
ciscocisco_iosMatch3.4.0sgxe
OR
ciscocisco_iosMatch3.4.2sgxe
OR
ciscocisco_iosMatch3.4.1sgxe
OR
ciscocisco_iosMatch3.4.3sgxe
OR
ciscocisco_iosMatch3.4.4sgxe
OR
ciscocisco_iosMatch3.4.5sgxe
OR
ciscocisco_iosMatch3.5.0exe
OR
ciscocisco_iosMatch3.5.1exe
OR
ciscocisco_iosMatch3.5.2exe
OR
ciscocisco_iosMatch3.5.3exe
OR
ciscocisco_iosMatch3.10.0sxe
OR
ciscocisco_iosMatch3.10.1sxe
OR
ciscocisco_iosMatch3.10.2sxe
OR
ciscocisco_iosMatch3.10.0asxe
OR
ciscocisco_iosMatch3.10.3sxe
OR
ciscocisco_iosMatch3.10.4sxe
OR
ciscocisco_iosMatch3.10.5sxe
OR
ciscocisco_iosMatch3.10.6sxe
OR
ciscocisco_iosMatch3.11.1sxe
OR
ciscocisco_iosMatch3.11.2sxe
OR
ciscocisco_iosMatch3.11.0sxe
OR
ciscocisco_iosMatch3.11.3sxe
OR
ciscocisco_iosMatch3.11.4sxe
OR
ciscocisco_iosMatch3.12.0sxe
OR
ciscocisco_iosMatch3.12.1sxe
OR
ciscocisco_iosMatch3.12.2sxe
OR
ciscocisco_iosMatch3.12.3sxe
OR
ciscocisco_iosMatch3.13.0sxe
OR
ciscocisco_iosMatch3.13.1sxe
OR
ciscocisco_iosMatch3.13.2sxe
OR
ciscocisco_iosMatch3.6.0exe
OR
ciscocisco_iosMatch3.6.1exe
OR
ciscocisco_iosMatch3.14.0sxe
OR
ciscocisco_iosMatch3.14.1sxe
OR
ciscocisco_iosMatch3.14.2sxe
OR
ciscocisco_iosMatch3.14.3sxe
OR
ciscocisco_iosMatch3.14.4sxe
OR
ciscocisco_iosMatch3.15.0sxe
OR
ciscocisco_iosMatch3.3.0sqxe
OR
ciscocisco_iosMatch3.3.1sqxe
OR
ciscocisco_iosMatch3.4.0sqxe
OR
ciscocisco_iosMatch3.4.1sqxe
OR
ciscocisco_iosMatch3.7.0exe
OR
ciscocisco_iosMatchanyxe
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
cisconetwork_analysis_module_softwareMatchany
OR
ciscoironport_encryption_applianceMatchany
OR
cisconetwork_admission_controlMatchany
OR
ciscotelepresence_mxp_softwareMatchany
OR
ciscoshow_and_shareMatchany
OR
ciscoidentity_services_engine_softwareMatchany
OR
ciscotelepresence_video_communication_serverMatchany
OR
ciscoweb_security_virtual_applianceMatch1000v_series_switches
OR
ciscotelepresence_managerMatchany
OR
ciscoasa_cx_context-aware_security_softwareMatchany
OR
ciscoprime_security_managerMatchany
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoprime_lan_management_solutionMatchany
OR
ciscoprime_collaborationMatchany
OR
ciscoprime_infrastructureMatchany
OR
ciscoconnected_grid_network_management_systemMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscowebex_node_for_mcsMatchany
OR
ciscounified_computing_system_central_softwareMatchany
OR
ciscoenterprise_content_delivery_systemMatchany
OR
ciscotelepresence_tc_softwareMatchany
OR
ciscotelepresence_te_softwareMatchany
OR
ciscovirtualization_experience_client_6000Match6000_series_firmware
OR
ciscofinesseMatchany
OR
ciscosocialminerMatchany
OR
ciscomediasenseMatchany
OR
ciscounified_sip_proxyMatchany
OR
ciscocisco_mxeMatch3500_\(media_experience_engine\)
OR
ciscoucs_directorMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscounified_intelligence_centerMatchany
OR
ciscoprime_service_catalogMatchany
OR
cisconexus_1000vMatch1000v_switchnexus_1000v
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
ciscoexpresswayMatchany
OR
ciscoedge_340_firmwareMatch300_series
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscounified_computing_system_softwareMatchany
OR
ciscoprime_license_managerMatchany
OR
ciscoprime_collaboration_deploymentMatchany
OR
ciscotelepresence_isdn_gw_3241Matchany
OR
ciscotelepresence_conductorMatchany
OR
ciscomodular_encoding_platform_d9036_softwareMatchany
OR
ciscofirepower_system_softwareMatchany
OR
ciscovideoscape_policy_resource_managerMatchany
OR
ciscoprime_collaboration_assuranceMatchany
OR
ciscovirtual_topology_systemMatchany
OR
cisconexus_1000vMatch3000_series_switchnexus_1000v
OR
ciscocisco_policy_suiteMatchany
OR
ciscohosted_collaboration_mediation_fulfillmentMatchany
OR
ciscocloud_services_platform_2100Match2100

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

7.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N

0.097 Low

EPSS

Percentile

94.8%