5.8
CVSSv3

CVE-2016-1321

Published: 15/02/2016 Updated: 06/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.8 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote malicious users to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID CSCut98082.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco universal small cell firmware r3.3 base

cisco universal small cell firmware r3.4 base

cisco universal small cell firmware r2.13 base

cisco universal small cell firmware r2.15 base

cisco universal small cell firmware r3.2 base

cisco universal small cell firmware r3.4 2.17

cisco universal small cell firmware r2.16 base

cisco universal small cell firmware r3.5 base

cisco universal small cell firmware r2.12 base

cisco universal small cell firmware r2.17 base

cisco universal small cell firmware r3.4 2.1

cisco universal small cell firmware r2.14 base

cisco universal small cell firmware r3.4 1.1

Vendor Advisories

A vulnerability in Cisco Universal Small Cell devices could allow an unauthenticated, remote attacker to retrieve firmware from a Cisco-hosted binary server The vulnerability is due to insufficient enforcement of the two-way certificate validation process by the Cisco-hosted binary server to ensure that only Cisco Universal Small Cell devices ar ...