First published: Thu Mar 24 2016(Updated: )
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 | =5.0.0 | |
Cisco IOS XRv 9000 | =5.0.1 | |
Cisco IOS XRv 9000 | =5.2.1 | |
Cisco IOS XRv 9000 | =5.2.3 | |
Cisco IOS XRv 9000 | =5.2.4 | |
Cisco IOS XRv 9000 | =5.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1366 has a high severity rating due to its potential to allow remote authenticated users to cause a denial of service.
To fix CVE-2016-1366, you should upgrade your Cisco IOS XR software to a version later than 5.2.5.
CVE-2016-1366 affects the SCP and SFTP modules in Cisco IOS XR versions 5.0.0 through 5.2.5 on Network Convergence System 6000 devices.
Yes, CVE-2016-1366 can be exploited remotely by authenticated users to overwrite system files.
Yes, CVE-2016-1366 is also known as Bug ID CSCuw75848.