CVE-2016-6412
published 2016-09-24CVE-2016-6412: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle…
PriorityP430medium6.5CVSS 3.0
AVNACLPRNUIRSUCNIHAN
EPSS
1.10%
62.4th percentile
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | application-hosting_framework_http_header | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v573-qcx7-25pj: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-6412 [MEDIUM] CWE-20 GHSA-v573-qcx7-25pj: The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.
Cisco
Cisco Application-Hosting Framework HTTP Header Injection Vulnerability
vendor_cisco·2016-09-21·CVSS 4.3
CVE-2016-6412 [MEDIUM] CWE-20 Cisco Application-Hosting Framework HTTP Header Injection Vulnerability
Cisco Application-Hosting Framework HTTP Header Injection Vulnerability
A vulnerability in the Cisco Application-hosting Framework (CAF) component for Cisco IOS and IOS XE Software with the IOx feature set could allow an unauthenticated, remote attacker to cause a CAF user to download a file controlled by the attacker.
The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting crafted HTTP headers into the communication path between the user and CAF. An exploit could allow the attacker to force the user to download a file controlled by the attacker.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available.
This advisory is available at the following link:
Cisco
Cisco Application-Hosting Framework HTTP Header Injection Vulnerability
vendor_cisco
CVE-2016-6412 Cisco Application-Hosting Framework HTTP Header Injection Vulnerability
CVE-2016-6412: Cisco Application-Hosting Framework HTTP Header Injection Vulnerability
A vulnerability in the Cisco Application-hosting Framework (CAF) component for Cisco IOS and IOS XE Software with the IOx feature set could allow an unauthenticated, remote attacker to cause a CAF user to download a file controlled by the attacker. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by injecting crafted HTTP headers into the communication path between the user and CAF. An exploit could allow the attacker to force the user to download a file controlled by the attacker. Cisco has released software updates that address this vulnerability.
CWE: CWE-20, CWE-20
Bug IDs: CSCuz84773
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-caf1http://www.securityfocus.com/bid/93088http://www.securitytracker.com/id/1036874http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-caf1http://www.securityfocus.com/bid/93088http://www.securitytracker.com/id/1036874
2016-09-24
Published