CVE-2016-6438
published 2016-10-27CVE-2016-6438: A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a…
PriorityP432medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.22%
65.6th percentile
A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a configuration integrity change to the vty line configuration on an affected device. This vulnerability affects the following releases of Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers: All 3.16S releases, All 3.17S releases, Release 3.18.0S, Release 3.18.1S, Release 3.18.0SP. More Information: CSCuz62815. Known Affected Releases: 15.5(3)S2.9, 15.6(2)SP. Known Fixed Releases: 15.6(1.7)SP1, 16.4(0.183), 16.5(0.1).
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cbr-8_converged_broadband_router_vty_integrity | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-65gc-9jw6-hwxx: A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a
ghsa_unreviewed·2022-05-17
CVE-2016-6438 [MEDIUM] GHSA-65gc-9jw6-hwxx: A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a
A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a configuration integrity change to the vty line configuration on an affected device. This vulnerability affects the following releases of Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers: All 3.16S releases, All 3.17S releases, Release 3.18.0S, Release 3.18.1S, Release 3.18.0SP. More Information: CSCuz62815. Known Affected Releases: 15.5(3)S2.9, 15.6(2)SP. Known Fixed Releases: 15.6(1.7)SP1, 16.4(0.183), 16.5(0.1).
Chrome
Stable Channel Update for Desktop: CVE-2020-6437
vendor_chrome·2020-04-07·CVSS 4.3
CVE-2020-6437 [LOW] Stable Channel Update for Desktop: CVE-2020-6437
Stable Channel Update for Desktop
CVE-2020-6437: Inappropriate implementation in WebView. Reported by Jann Horn on 2016-08-19
[$500][ 714617 ] Low CVE-2020-6438: Insufficient policy enforcement in extensions
Reported by Ng Yik Phang on 2017-04-24
Severity: low
Cisco
Cisco cBR-8 Converged Broadband Router vty Integrity Vulnerability
vendor_cisco·2016-10-12·CVSS 4.3
CVE-2016-6438 [MEDIUM] CWE-264 Cisco cBR-8 Converged Broadband Router vty Integrity Vulnerability
Cisco cBR-8 Converged Broadband Router vty Integrity Vulnerability
A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a configuration integrity change to the vty line configuration on an affected device.
The vulnerability is due to a logic processing error that exists if an affected device is configured with the Downstream Resiliency and Downstream Resiliency Bonding Group features. An attacker could exploit this vulnerability by continuously trying to establish Telnet or SSH connections to a targeted device. A successful exploit could allow the attacker to trigger an integrity issue with the vty line configuration.
Cisco has released software updates that address this vulnerability. There
Cisco
Cisco cBR-8 Converged Broadband Router vty Integrity Vulnerability
vendor_cisco
CVE-2016-6438 Cisco cBR-8 Converged Broadband Router vty Integrity Vulnerability
CVE-2016-6438: Cisco cBR-8 Converged Broadband Router vty Integrity Vulnerability
A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a configuration integrity change to the vty line configuration on an affected device. The vulnerability is due to a logic processing error that exists if an affected device is configured with the Downstream Resiliency and Downstream Resiliency Bonding Group features. An attacker could exploit this vulnerability by continuously trying to establish Telnet or SSH connections to a targeted device. A successful exploit could allow the attacker to trigger an integrity issue with the vty line configuration. Cisco has released software updates that address this vulnerabi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/93518http://www.securitytracker.com/id/1037003https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-cbr-8http://www.securityfocus.com/bid/93518http://www.securitytracker.com/id/1037003https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161012-cbr-8
2016-10-27
Published