CVE-2016-6406
published 2016-09-22CVE-2016-6406: Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices…
PriorityP262critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.57%
88.1th percentile
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_firmware | — | — |
| cisco | email_security_appliance_internal_testing_interface | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by monitoring for unexpected connections to the Cisco ESA internal testing and debugging interface, which should not be accessible on production devices ↗
- →Flag any unauthenticated remote connections that result in root-level access on Cisco ESA devices running AsyncOS versions 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, or 10.0.0-125 with Enrollment Client before 1.0.2-065 ↗
- ·Vulnerability is only present when Enrollment Client before version 1.0.2-065 is installed alongside the affected AsyncOS versions; upgrading the Enrollment Client to 1.0.2-065 or later mitigates the issue ↗
- ·The internal testing and debugging interface was intended solely for use during product manufacturing and should not be present in customer-available software releases; its presence on production builds is the root cause of this vulnerability ↗
- ·A workaround is available in addition to the software update; operators should consult the Cisco advisory for workaround details ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Email Security Appliance Internal Testing Interface Vulnerability
vendor_cisco·2016-09-22·CVSS 10.0
CVE-2016-6406 [CRITICAL] Cisco Email Security Appliance Internal Testing Interface Vulnerability
Cisco Email Security Appliance Internal Testing Interface Vulnerability
A vulnerability in Cisco IronPort AsyncOS for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to obtain complete control of an affected device.
The vulnerability is due to the presence of a Cisco internal testing and debugging interface (intended for use during product manufacturing only) on customer-available software releases. An attacker could exploit this vulnerability by connecting to this testing and debugging interface. An exploit could allow an attacker to obtain complete control of an affected device with root-level privileges.
Cisco has released software updates that address this vulnerability. A workaround that mitigates this vulnerability is available.
This advisory
Cisco
Cisco Email Security Appliance Internal Testing Interface Vulnerability
vendor_cisco
CVE-2016-6406 Cisco Email Security Appliance Internal Testing Interface Vulnerability
CVE-2016-6406: Cisco Email Security Appliance Internal Testing Interface Vulnerability
A vulnerability in Cisco IronPort AsyncOS for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to obtain complete control of an affected device. The vulnerability is due to the presence of a Cisco internal testing and debugging interface (intended for use during product manufacturing only) on customer-available software releases. An attacker could exploit this vulnerability by connecting to this testing and debugging interface. An exploit could allow an attacker to obtain complete control of an affected device with root -level privileges. Cisco has released software updates that address this vulnerability. A workaround that mitigates this vulnerability is available. T
GHSA
GHSA-vp5v-r76g-m4mx: Cisco IronPort AsyncOS 9
ghsa_unreviewed·2022-05-17
CVE-2016-6406 [CRITICAL] GHSA-vp5v-r76g-m4mx: Cisco IronPort AsyncOS 9
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160922-esahttp://www.securityfocus.com/bid/93116http://www.securitytracker.com/id/1036881http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160922-esahttp://www.securityfocus.com/bid/93116http://www.securitytracker.com/id/1036881
2016-09-22
Published