Lucene search

K
ciscoCiscoCISCO-SA-20161026-LINUX
HistoryOct 26, 2016 - 3:00 p.m.

Vulnerability in Linux Kernel Affecting Cisco Products: October 2016

2016-10-2615:00:00
tools.cisco.com
60

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.879 High

EPSS

Percentile

98.7%

On October 19, 2016, a new vulnerability related to a race condition in the memory manager of the Linux Kernel was disclosed. This vulnerability could allow unprivileged, local users to gain write access to otherwise read-only memory mappings to increase their privileges on the system.

Cisco has released software updates that address this vulnerability. For information about affected and fixed software releases, consult the Cisco bug IDs in the Vulnerable Products table.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-linux [“https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-linux”]

Affected configurations

Vulners
Node
ciscoprime_access_registrarMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscomobility_services_engineMatchany
OR
ciscotelepresence_video_communication_serverMatchanycontrol
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoata_187_analog_telephone_adaptorMatchany
OR
ciscowebex_meetings_serverMatchany
OR
ciscovirtualization_experience_media_engineMatchany
OR
ciscoucs_directorMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscoprime_service_catalogMatchany
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
ciscoexpresswayMatchany
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscongips_virtual_applianceMatchany
OR
ciscoprime_collaboration_provisioningMatchany
OR
ciscoprime_networkMatchany
OR
ciscoip_phone_8800_seriesMatchany
OR
ciscopaging_serverMatchany
OR
ciscocisco_spa112Matchany
OR
ciscoataMatchany
OR
ciscoataMatchany
OR
ciscovideoscape_distribution_suite_service_managerMatchany
OR
ciscocisco_policy_suiteMatchany
OR
ciscoprime_access_registrarMatchany
OR
ciscoip_interoperability_and_collaboration_systemMatchany
OR
ciscovideo_surveillance_media_serverMatchany
OR
ciscodigital_media_managerMatchany
OR
ciscomobility_services_engineMatchany
OR
ciscotelepresence_video_communication_serverMatchanycontrol
OR
ciscoprime_data_center_network_managerMatchany
OR
ciscoataMatch187_analog_telephone_adaptor
OR
ciscowebex_meetings_serverMatchany
OR
ciscocisco_mxeMatch3500_\(media_experience_engine\)
OR
ciscoucs_directorMatchany
OR
ciscovideoscape_distribution_suite_service_brokerMatchany
OR
ciscodigital_content_managerMatchany
OR
ciscoprime_service_catalogMatchany
OR
ciscoapplication_policy_infrastructure_controller_\(apic\)Matchany
OR
ciscoexpresswayMatchany
OR
ciscojabber_guestMatchany
OR
ciscodesktop_collaboration_experienceMatchany
OR
ciscongips_virtual_applianceMatchany
OR
ciscoprime_collaboration_provisioningMatchany
OR
ciscoprime_networkMatchany
OR
ciscoip_phone_8800_seriesMatchany
OR
ciscopaging_serverMatchany
OR
ciscocisco_spa112Match2-port_phone_adapter
OR
ciscoataMatchany
OR
ciscoataMatchany
OR
ciscovideoscape_distribution_suite_service_managerMatchany
OR
ciscocisco_policy_suiteMatchany

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.879 High

EPSS

Percentile

98.7%