SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-6361

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170.

MEDIUM 6.5EPSS 1.44%

Does this matter?

Lower severity and a low EPSS score (1.44%). Track it; it rarely justifies an emergency change on its own.

Description

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary commands via unspecified fields, aka Bug ID CSCuw86170.

CVSS 2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
1.44% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cisco/dpc3939 wireless residential voice gateway firmware
Source
psirt@cisco.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.