cbcvebase.
CVE-2016-1335
published 2016-02-19

CVE-2016-1335: The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication…

PriorityP348high7.5CVSS 3.0
AVNACHPRLUINSUCHIHAH
EPSS
3.38%
87.4th percentile
The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a connection from an endpoint that was previously used for an administrator's connection, aka Bug ID CSCux22492.

Affected

7 ranges
VendorProductVersion rangeFixed in
ciscoasr_5000_series_software
ciscoasr_5000_series_software
ciscoasr_5000_series_software
ciscoasr_5000_series_software
ciscoasr_5000_series_software
ciscoasr_5000_series_software
ciscoasr_5000_series_staros_ssh_subsystem

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.1HIGHAV:N/AC:H/Au:S/C:C/I:C/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.