CVE-2016-6397
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote attacker to modify configuration parameters of the UMS and cause the system to become unavailable. Affected Products: This vulnerability affects Cisco IPICS releases 4.8(1) to 4.10(1). More Information: CSCva46644. Known Affected Releases: 4.10(1) 4.8(1) 4.8(2) 4.9(1) 4.9(2).
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@cisco.com — https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-ipics
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cisco | ip_interoperability_and_collaboration_system | 4.8\(1\) | |
| cisco | ip_interoperability_and_collaboration_system | 4.8\(2\) | |
| cisco | ip_interoperability_and_collaboration_system | 4.9\(1\) | |
| cisco | ip_interoperability_and_collaboration_system | 4.9\(2\) | |
| cisco | ip_interoperability_and_collaboration_system | 4.10\(1\) | |
References
CWEs
CWE-287
Verify integrity in audit chain (admin only). AS-IS.