6.5

CVE-2016-1452

Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Cisco ≫ Asr 5000 Version -
Cisco ≫ Asr 5000 Software Version 18.3.0
Cisco ≫ Asr 5000 Software Version 18.3_base
Cisco ≫ Asr 5000 Software Version 19.0.1
Cisco ≫ Asr 5000 Software Version 19.0.m0.60737
Cisco ≫ Asr 5000 Software Version 19.0.m0.60828
Cisco ≫ Asr 5000 Software Version 19.0.m0.61045
Cisco ≫ Asr 5000 Software Version 19.1.0
Cisco ≫ Asr 5000 Software Version 19.1.0.61559
Cisco ≫ Asr 5000 Software Version 19.2.0
Cisco ≫ Asr 5000 Software Version 19.3.0
Cisco ≫ Asr 5000 Software Version 20.0.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.611
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 3.9 2.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160713-asr
Vendor Advisory
http://www.securityfocus.com/bid/91756
http://www.securitytracker.com/id/1036298