CVE-2016-1452

medium
Published 2016-07-15 · Modified 2026-05-06
CVSS v3
6.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS v2
6.4
VIR risk
6.5

Description

Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160713-asr

Application impact

VendorProductVersionsFixed
cisco ciscoasr_5000_software18.3.0
cisco ciscoasr_5000_software18.3_base
cisco ciscoasr_5000_software19.0.1
cisco ciscoasr_5000_software19.0.m0.60737
cisco ciscoasr_5000_software19.0.m0.60828
cisco ciscoasr_5000_software19.0.m0.61045
cisco ciscoasr_5000_software19.1.0
cisco ciscoasr_5000_software19.1.0.61559
cisco ciscoasr_5000_software19.2.0
cisco ciscoasr_5000_software19.3.0
cisco ciscoasr_5000_software20.0.0

References

CWEs

CWE-200 CWE-254

Verify integrity in audit chain (admin only). AS-IS.