10
CVSSv2

CVE-2016-6406

Published: 22/09/2016 Updated: 30/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client prior to 1.0.2-065 is installed, allows remote malicious users to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco email security appliance firmware 9.1.2-036

cisco email security appliance firmware 9.7.2-046

cisco email security appliance firmware 10.0.0-124

cisco email security appliance firmware 10.0.0-125

cisco email security appliance firmware 9.1.2-023

cisco email security appliance firmware 9.1.2-028

cisco email security appliance firmware 9.7.2-047

cisco email security appliance firmware 9.7.2-054

Vendor Advisories

A vulnerability in Cisco IronPort AsyncOS for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to obtain complete control of an affected device The vulnerability is due to the presence of a Cisco internal testing and debugging interface (intended for use during product manufacturing only) on customer-available ...