7.5
CVE-2016-1335
- EPSS 2.91%
- Veröffentlicht 19.02.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle psirt@cisco.com
- Teams Watchlist Login
- Unerledigt Login
The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a connection from an endpoint that was previously used for an administrator's connection, aka Bug ID CSCux22492.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Asr 5000 Series Software Version16.5.2
Cisco ≫ Asr 5000 Series Software Version17.7.0
Cisco ≫ Asr 5000 Series Software Version18.4.0
Cisco ≫ Asr 5000 Series Software Version19.0.1
Cisco ≫ Asr 5000 Series Software Version19.3.0
Cisco ≫ Asr 5000 Series Software Version20.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 2.91% | 0.858 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 1.6 | 5.9 |
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.1 | 3.9 | 10 |
AV:N/AC:H/Au:S/C:C/I:C/A:C
|