Lucene search

K
cveCiscoCVE-2016-9196
HistoryApr 07, 2017 - 5:59 p.m.

CVE-2016-9196

2017-04-0717:59:00
CWE-264
cisco
web.nvd.nist.gov
25
4
cisco
aironet
access point
vulnerability
root access
authentication
linux
cve-2016-9196.

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

5.1%

A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms could allow an authenticated, local attacker to gain unrestricted root access to the underlying Linux operating system. The root Linux shell is provided for advanced troubleshooting and should not be available to individual users, even those with root privileges. The attacker must have the root password to exploit this vulnerability. More Information: CSCvb13893. Known Affected Releases: 8.2(121.0) 8.3(102.0). Known Fixed Releases: 8.4(1.53) 8.4(1.52) 8.3(111.0) 8.3(104.23) 8.2(130.0) 8.2(124.1).

Affected configurations

Nvd
Node
ciscoaironet_access_pointMatch8.1\(15.14\)
OR
ciscoaironet_access_pointMatch8.1\(112.3\)
OR
ciscoaironet_access_pointMatch8.1\(112.4\)
OR
ciscoaironet_access_pointMatch8.1\(131.0\)
OR
ciscoaironet_access_pointMatch8.2\(100.0\)
OR
ciscoaironet_access_pointMatch8.2\(102.43\)
OR
ciscoaironet_access_pointMatch8.2_base
AND
ciscoaironet_1800Match-
OR
ciscoaironet_2800eMatch-
OR
ciscoaironet_2800iMatch-
OR
ciscoaironet_3800eMatch-
OR
ciscoaironet_3800iMatch-
OR
ciscoaironet_3800pMatch-
VendorProductVersionCPE
ciscoaironet_access_point8.1(15.14)cpe:2.3:o:cisco:aironet_access_point:8.1\(15.14\):*:*:*:*:*:*:*
ciscoaironet_access_point8.1(112.3)cpe:2.3:o:cisco:aironet_access_point:8.1\(112.3\):*:*:*:*:*:*:*
ciscoaironet_access_point8.1(112.4)cpe:2.3:o:cisco:aironet_access_point:8.1\(112.4\):*:*:*:*:*:*:*
ciscoaironet_access_point8.1(131.0)cpe:2.3:o:cisco:aironet_access_point:8.1\(131.0\):*:*:*:*:*:*:*
ciscoaironet_access_point8.2(100.0)cpe:2.3:o:cisco:aironet_access_point:8.2\(100.0\):*:*:*:*:*:*:*
ciscoaironet_access_point8.2(102.43)cpe:2.3:o:cisco:aironet_access_point:8.2\(102.43\):*:*:*:*:*:*:*
ciscoaironet_access_point8.2_basecpe:2.3:o:cisco:aironet_access_point:8.2_base:*:*:*:*:*:*:*
ciscoaironet_1800-cpe:2.3:h:cisco:aironet_1800:-:*:*:*:*:*:*:*
ciscoaironet_2800e-cpe:2.3:h:cisco:aironet_2800e:-:*:*:*:*:*:*:*
ciscoaironet_2800i-cpe:2.3:h:cisco:aironet_2800i:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CNA Affected

[
  {
    "product": "Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms"
      }
    ]
  }
]

Social References

More

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

6.7

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

6.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2016-9196