6.8
CVSSv2

CVE-2016-1366

Published: 24/03/2016 Updated: 03/12/2016
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:L/Au:S/C:N/I:C/A:N

Vulnerability Summary

The SCP and SFTP modules in Cisco IOS XR 5.0.0 up to and including 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr 5.2.4

cisco ios xr 5.2.5

cisco ios xr 5.0.1

cisco ios xr 5.0.0

cisco ios xr 5.2.3

cisco ios xr 5.2.1