Lucene search

K
cveCiscoCVE-2016-6377
HistorySep 03, 2016 - 8:59 p.m.

CVE-2016-6377

2016-09-0320:59:08
CWE-287
cisco
web.nvd.nist.gov
18
cve-2016-6377
cisco
vmp
authentication bypass
security vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.004

Percentile

74.2%

Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and make arbitrary Platform and Applications Manager (PAM) API calls via unspecified vectors, aka Bug ID CSCuz52110.

Affected configurations

Nvd
Node
ciscomedia_origination_system_suiteMatch2.3\(1\)
OR
ciscomedia_origination_system_suiteMatch2.3\(2\)
OR
ciscomedia_origination_system_suiteMatch2.3\(6\)
OR
ciscomedia_origination_system_suiteMatch2.3\(7\)
OR
ciscomedia_origination_system_suiteMatch2.3\(8\)
OR
ciscomedia_origination_system_suiteMatch2.3_base
OR
ciscomedia_origination_system_suiteMatch2.4\(1\)
OR
ciscomedia_origination_system_suiteMatch2.4_base
OR
ciscomedia_origination_system_suiteMatch2.5\(0\)
OR
ciscomedia_origination_system_suiteMatch2.5\(1\)
OR
ciscomedia_origination_system_suiteMatch2.5_base
OR
ciscomedia_origination_system_suiteMatch2.6_base
VendorProductVersionCPE
ciscomedia_origination_system_suite2.3(1)cpe:2.3:a:cisco:media_origination_system_suite:2.3\(1\):*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.3(2)cpe:2.3:a:cisco:media_origination_system_suite:2.3\(2\):*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.3(6)cpe:2.3:a:cisco:media_origination_system_suite:2.3\(6\):*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.3(7)cpe:2.3:a:cisco:media_origination_system_suite:2.3\(7\):*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.3(8)cpe:2.3:a:cisco:media_origination_system_suite:2.3\(8\):*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.3_basecpe:2.3:a:cisco:media_origination_system_suite:2.3_base:*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.4(1)cpe:2.3:a:cisco:media_origination_system_suite:2.4\(1\):*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.4_basecpe:2.3:a:cisco:media_origination_system_suite:2.4_base:*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.5(0)cpe:2.3:a:cisco:media_origination_system_suite:2.5\(0\):*:*:*:*:*:*:*
ciscomedia_origination_system_suite2.5(1)cpe:2.3:a:cisco:media_origination_system_suite:2.5\(1\):*:*:*:*:*:*:*
Rows per page:
1-10 of 121

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.2

Confidence

High

EPSS

0.004

Percentile

74.2%

Related for CVE-2016-6377