CVE Vulnerabilities

CVE-2016-1366

Published: Mar 24, 2016 | Modified: Dec 03, 2016
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
6.8 MEDIUM
AV:N/AC:L/Au:S/C:N/I:C/A:N
RedHat/V2
RedHat/V3
Ubuntu

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

Affected Software

Name Vendor Start Version End Version
Ios_xr Cisco 5.2.5 5.2.5
Ios_xr Cisco 5.2.4 5.2.4
Ios_xr Cisco 5.0.1 5.0.1
Ios_xr Cisco 5.2.1 5.2.1
Ios_xr Cisco 5.0.0 5.0.0
Ios_xr Cisco 5.2.3 5.2.3

References