5
CVSSv2

CVE-2016-1321

Published: 15/02/2016 Updated: 06/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.8 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote malicious users to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID CSCut98082.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco universal small cell firmware r3.4_base

cisco universal small cell firmware r3.3_base

cisco universal small cell firmware r2.12_base

cisco universal small cell firmware r3.4_2.17

cisco universal small cell firmware r3.4_2.1

cisco universal small cell firmware r2.16_base

cisco universal small cell firmware r2.15_base

cisco universal small cell firmware r3.4_1.1

cisco universal small cell firmware r3.5_base

cisco universal small cell firmware r2.14_base

cisco universal small cell firmware r2.13_base

cisco universal small cell firmware r3.2_base

cisco universal small cell firmware r2.17_base

Vendor Advisories

A vulnerability in Cisco Universal Small Cell devices could allow an unauthenticated, remote attacker to retrieve firmware from a Cisco-hosted binary server The vulnerability is due to insufficient enforcement of the two-way certificate validation process by the Cisco-hosted binary server to ensure that only Cisco Universal Small Cell devices ar ...