CVE-2016-6410
published 2016-09-24CVE-2016-6410: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated…
PriorityP336medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.40%
69.7th percentile
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios_and_ios_xe | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:C/I:N/A:N
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS and IOS XE Software Application-Hosting Framework Unauthorized File Access Vulnerability
vendor_cisco·2016-09-21·CVSS 6.8
CVE-2016-6410 [MEDIUM] CWE-20 Cisco IOS and IOS XE Software Application-Hosting Framework Unauthorized File Access Vulnerability
Cisco IOS and IOS XE Software Application-Hosting Framework Unauthorized File Access Vulnerability
A vulnerability in the Cisco application-hosting framework (CAF) for Cisco IOS and IOS XE Software with the IOx feature set could allow an authenticated, remote attacker to read arbitrary files on a targeted system.
The vulnerability is due to insufficient input validation by the affected framework. An attacker could exploit this vulnerability by submitting specific, crafted input to the affected framework. A successful exploit could allow the attacker to read arbitrary files on the targeted system.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cl
Cisco
Cisco IOS and IOS XE Software Application-Hosting Framework Unauthorized File Access Vulnerability
vendor_cisco
CVE-2016-6410 Cisco IOS and IOS XE Software Application-Hosting Framework Unauthorized File Access Vulnerability
CVE-2016-6410: Cisco IOS and IOS XE Software Application-Hosting Framework Unauthorized File Access Vulnerability
A vulnerability in the Cisco application-hosting framework (CAF) for Cisco IOS and IOS XE Software with the IOx feature set could allow an authenticated, remote attacker to read arbitrary files on a targeted system. The vulnerability is due to insufficient input validation by the affected framework. An attacker could exploit this vulnerability by submitting specific, crafted input to the affected framework. A successful exploit could allow the attacker to read arbitrary files on the targeted system. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-20, CWE-20
Bug IDs: CSCuy19856
GHSA
GHSA-mpxw-9793-rp52: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-6410 [MEDIUM] CWE-20 GHSA-mpxw-9793-rp52: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-cafhttp://www.securityfocus.com/bid/93090http://www.securitytracker.com/id/1036873http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-cafhttp://www.securityfocus.com/bid/93090http://www.securitytracker.com/id/1036873
2016-09-24
Published