CVE-2016-1366: Medium severity cisco ios xrv 9000 vulnerability
The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1366?
CVE-2016-1366 has a high severity rating due to its potential to allow remote authenticated users to cause a denial of service.
How do I fix CVE-2016-1366?
To fix CVE-2016-1366, you should upgrade your Cisco IOS XR software to a version later than 5.2.5.
What does CVE-2016-1366 affect?
CVE-2016-1366 affects the SCP and SFTP modules in Cisco IOS XR versions 5.0.0 through 5.2.5 on Network Convergence System 6000 devices.
Can CVE-2016-1366 be exploited remotely?
Yes, CVE-2016-1366 can be exploited remotely by authenticated users to overwrite system files.
Is CVE-2016-1366 a known bug?
Yes, CVE-2016-1366 is also known as Bug ID CSCuw75848.