Lucene search

K
cveCiscoCVE-2016-1335
HistoryFeb 19, 2016 - 7:59 p.m.

CVE-2016-1335

2016-02-1919:59:03
CWE-264
cisco
web.nvd.nist.gov
23
cisco
staros
ssh
implementation
vulnerability
cve-2016-1335
asr 5000
nvd

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

47.6%

The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a connection from an endpoint that was previously used for an administrator’s connection, aka Bug ID CSCux22492.

Affected configurations

Nvd
Node
ciscoasr_5000_series_softwareMatch16.5.2
OR
ciscoasr_5000_series_softwareMatch17.7.0
OR
ciscoasr_5000_series_softwareMatch18.4.0
OR
ciscoasr_5000_series_softwareMatch19.0.1
OR
ciscoasr_5000_series_softwareMatch19.3.0
OR
ciscoasr_5000_series_softwareMatch20.0.0
VendorProductVersionCPE
ciscoasr_5000_series_software16.5.2cpe:2.3:a:cisco:asr_5000_series_software:16.5.2:*:*:*:*:*:*:*
ciscoasr_5000_series_software17.7.0cpe:2.3:a:cisco:asr_5000_series_software:17.7.0:*:*:*:*:*:*:*
ciscoasr_5000_series_software18.4.0cpe:2.3:a:cisco:asr_5000_series_software:18.4.0:*:*:*:*:*:*:*
ciscoasr_5000_series_software19.0.1cpe:2.3:a:cisco:asr_5000_series_software:19.0.1:*:*:*:*:*:*:*
ciscoasr_5000_series_software19.3.0cpe:2.3:a:cisco:asr_5000_series_software:19.3.0:*:*:*:*:*:*:*
ciscoasr_5000_series_software20.0.0cpe:2.3:a:cisco:asr_5000_series_software:20.0.0:*:*:*:*:*:*:*

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:S/C:C/I:C/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

47.6%

Related for CVE-2016-1335