5
CVSSv2

CVE-2016-1378

Published: 14/04/2016 Updated: 03/12/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cisco IOS prior to 15.2(2)E1 on Catalyst switches allows remote malicious users to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62591.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios 15.1\\(2\\)sg

cisco ios 15.1\\(1\\)sg1

cisco ios 15.1\\(2\\)sy

cisco ios 15.1\\(2\\)sg3

cisco ios 15.1\\(1\\)sy3

cisco ios 15.1\\(2\\)sy5

cisco ios 15.1\\(2\\)sg6

cisco ios 15.1\\(1\\)sy

cisco ios 15.1\\(2\\)sy1

cisco ios 15.1\\(2\\)sy2

cisco ios 15.1\\(2\\)sy3

cisco ios 15.1\\(1\\)sy4

cisco ios 15.1\\(1\\)sy6

cisco ios 15.1\\(2\\)sy6

cisco ios 15.1\\(1\\)sg

cisco ios 15.1\\(1\\)sy1

cisco ios 15.1\\(1\\)sy2

cisco ios 15.1\\(2\\)sg2

cisco ios 15.1\\(2\\)sy4

cisco ios 15.1\\(1\\)sy5

cisco ios 15.1\\(2\\)sy7

cisco ios 15.1\\(2\\)sy8

cisco ios 15.1\\(1\\)sg2

cisco ios 15.1\\(2\\)sg1

cisco ios 15.1\\(2\\)sg4

cisco ios 15.1\\(2\\)sg5

cisco ios 15.1\\(2\\)sy4a

cisco ios 15.1\\(2\\)sg7

Vendor Advisories

Cisco Catalyst Switches running Cisco IOS Software releases prior to 152(2)E1 may allow an unauthenticated, remote attacker to retrieve version information about the software release running on the device by accessing the Network Mobility Services Protocol (NMSP) port The vulnerability is due to a failure to properly secure NMSP with authenticat ...