CVE-2016-6397

critical
Published 2016-10-28 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
10.0
VIR risk
9.8

Description

A vulnerability in the interdevice communications interface of the Cisco IP Interoperability and Collaboration System (IPICS) Universal Media Services (UMS) could allow an unauthenticated, remote attacker to modify configuration parameters of the UMS and cause the system to become unavailable. Affected Products: This vulnerability affects Cisco IPICS releases 4.8(1) to 4.10(1). More Information: CSCva46644. Known Affected Releases: 4.10(1) 4.8(1) 4.8(2) 4.9(1) 4.9(2).

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@cisco.com — https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-ipics

Application impact

VendorProductVersionsFixed
ciscoip_interoperability_and_collaboration_system4.8\(1\)
ciscoip_interoperability_and_collaboration_system4.8\(2\)
ciscoip_interoperability_and_collaboration_system4.9\(1\)
ciscoip_interoperability_and_collaboration_system4.9\(2\)
ciscoip_interoperability_and_collaboration_system4.10\(1\)

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.