VulnerabilityModified
CVE-2016-1452
Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.
MEDIUM 6.5EPSS 1.09%
Does this matter?
Lower severity and a low EPSS score (1.09%). Track it; it rarely justifies an emergency change on its own.
Description
Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 1.09% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-254
- Affected
- cisco/asr 5000 · cisco/asr 5000 software
- Source
- psirt@cisco.com
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160713-asrVendor Advisory
- http://www.securityfocus.com/bid/91756
- http://www.securitytracker.com/id/1036298
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160713-asrVendor Advisory
- http://www.securityfocus.com/bid/91756
- http://www.securitytracker.com/id/1036298
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.