CVE-2016-9223: Critical severity cisco cloudcenter vulnerability
A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow an unauthenticated, remote attacker to install Docker containers with high privileges on the affected system. Affected Products: This vulnerability affect all releases of Cisco CloudCenter Orchestrator (CCO) deployments where the Docker Engine TCP port 2375 is open on the system and bound to local address 0.0.0.0 (any interface).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9223?
CVE-2016-9223 is classified as a critical severity vulnerability due to its potential for unauthorized access and control.
How do I fix CVE-2016-9223?
To fix CVE-2016-9223, it is recommended to upgrade to the latest version of Cisco CloudCenter Orchestrator that addresses this vulnerability.
What are the potential impacts of CVE-2016-9223?
The potential impacts of CVE-2016-9223 include unauthorized installation of Docker containers with high privileges, leading to system compromise.
Which versions of Cisco CloudCenter are affected by CVE-2016-9223?
CVE-2016-9223 affects Cisco CloudCenter Orchestrator versions 4.4.0, 4.5.0, 4.6.0, and 4.6.1.
Is CVE-2016-9223 exploitable remotely?
Yes, CVE-2016-9223 can be exploited by unauthenticated remote attackers.