Lucene search

K
cveCiscoCVE-2016-6362
HistoryAug 22, 2016 - 10:59 a.m.

CVE-2016-6362

2016-08-2210:59:11
CWE-264
cisco
web.nvd.nist.gov
25
4
cisco
aironet
cve-2016-6362
privilege escalation
nvd
bug id cscuz24725

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to gain privileges via crafted CLI parameters, aka Bug ID CSCuz24725.

Affected configurations

Nvd
Node
ciscoaironet_access_point_softwareMatch8.1\(15.14\)
OR
ciscoaironet_access_point_softwareMatch8.1\(112.3\)
OR
ciscoaironet_access_point_softwareMatch8.1\(112.4\)
OR
ciscoaironet_access_point_softwareMatch8.1\(131.0\)
OR
ciscoaironet_access_point_softwareMatch8.2\(100.0\)
OR
ciscoaironet_access_point_softwareMatch8.2\(102.43\)
OR
ciscoaironet_access_point_softwareMatch8.3.0
VendorProductVersionCPE
ciscoaironet_access_point_software8.1(15.14)cpe:2.3:a:cisco:aironet_access_point_software:8.1\(15.14\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.1(112.3)cpe:2.3:a:cisco:aironet_access_point_software:8.1\(112.3\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.1(112.4)cpe:2.3:a:cisco:aironet_access_point_software:8.1\(112.4\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.1(131.0)cpe:2.3:a:cisco:aironet_access_point_software:8.1\(131.0\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.2(100.0)cpe:2.3:a:cisco:aironet_access_point_software:8.2\(100.0\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.2(102.43)cpe:2.3:a:cisco:aironet_access_point_software:8.2\(102.43\):*:*:*:*:*:*:*
ciscoaironet_access_point_software8.3.0cpe:2.3:a:cisco:aironet_access_point_software:8.3.0:*:*:*:*:*:*:*

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2016-6362