CVE-2016-1335
published 2016-02-19CVE-2016-1335: The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication…
PriorityP348high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
3.38%
87.4th percentile
The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a connection from an endpoint that was previously used for an administrator's connection, aka Bug ID CSCux22492.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_software | — | — |
| cisco | asr_5000_series_staros_ssh_subsystem | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8vpj-6xx8-gx4p: The SSH implementation in Cisco StarOS before 19
ghsa_unreviewed·2022-05-17
CVE-2016-1335 [HIGH] GHSA-8vpj-6xx8-gx4p: The SSH implementation in Cisco StarOS before 19
The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a connection from an endpoint that was previously used for an administrator's connection, aka Bug ID CSCux22492.
Cisco
Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
vendor_cisco·2016-02-18·CVSS 7.1
CVE-2016-1335 [HIGH] CWE-264 Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
A privilege escalation vulnerability in the SSH subsystem in Cisco ASR 5000 Series devices running StarOS could allow an authenticated, remote attacker to elevate privileges. The attacker would need to have a valid and configured SSH authorized key and access to the same device from which the privileged administrator connects.
The vulnerability is due to an error that occurs when multiple users are configured to use SSH keys as the authentication mechanism. Administrative accounts configured in this manner are tied to a single remote device. A successful attack could allow a lower-privileged user to authenticate as a higher-privileged administrator if all constraints can be met.
Cisco has released software upd
Cisco
Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
vendor_cisco
CVE-2016-1335 Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
CVE-2016-1335: Cisco ASR 5000 Series StarOS SSH Subsystem Privilege Escalation Vulnerability
A privilege escalation vulnerability in the SSH subsystem in Cisco ASR 5000 Series devices running StarOS could allow an authenticated, remote attacker to elevate privileges. The attacker would need to have a valid and configured SSH authorized key and access to the same device from which the privileged administrator connects. The vulnerability is due to an error that occurs when multiple users are configured to use SSH keys as the authentication mechanism. Administrative accounts configured in this manner are tied to a single remote device. A successful attack could allow a lower-privileged user to authenticate as a higher-privileged administrator if all constraints can be met. Cisco has released
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-02-19
Published