cbcvebase.
CVE-2016-6406
published 2016-09-22

CVE-2016-6406: Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices…

PriorityP262critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.57%
88.1th percentile
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.

Affected

9 ranges
VendorProductVersion rangeFixed in
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_firmware
ciscoemail_security_appliance_internal_testing_interface

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts by monitoring for unexpected connections to the Cisco ESA internal testing and debugging interface, which should not be accessible on production devices
  • Flag any unauthenticated remote connections that result in root-level access on Cisco ESA devices running AsyncOS versions 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, or 10.0.0-125 with Enrollment Client before 1.0.2-065
  • ·Vulnerability is only present when Enrollment Client before version 1.0.2-065 is installed alongside the affected AsyncOS versions; upgrading the Enrollment Client to 1.0.2-065 or later mitigates the issue
  • ·The internal testing and debugging interface was intended solely for use during product manufacturing and should not be present in customer-available software releases; its presence on production builds is the root cause of this vulnerability
  • ·A workaround is available in addition to the software update; operators should consult the Cisco advisory for workaround details

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.