CVE Vulnerabilities

CVE-2016-6397

Improper Authentication

Published: Oct 28, 2016 | Modified: Nov 28, 2016
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote attacker to modify configuration parameters of the UMS and cause the system to become unavailable. Affected Products: This vulnerability affects Cisco IPICS releases 4.8(1) to 4.10(1). More Information: CSCva46644. Known Affected Releases: 4.10(1) 4.8(1) 4.8(2) 4.9(1) 4.9(2).

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Ip_interoperability_and_collaboration_system Cisco 4.8(1) (including) 4.8(1) (including)
Ip_interoperability_and_collaboration_system Cisco 4.8(2) (including) 4.8(2) (including)
Ip_interoperability_and_collaboration_system Cisco 4.9(1) (including) 4.9(1) (including)
Ip_interoperability_and_collaboration_system Cisco 4.9(2) (including) 4.9(2) (including)
Ip_interoperability_and_collaboration_system Cisco 4.10(1) (including) 4.10(1) (including)

Potential Mitigations

References