Vulnerability Name: | CVE-2016-9201 (CCN-119546) | ||||||||||||
Assigned: | 2016-12-07 | ||||||||||||
Published: | 2016-12-07 | ||||||||||||
Updated: | 2016-12-22 | ||||||||||||
Summary: | A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass traffic that should otherwise have been dropped based on the configuration. More Information: CSCuz21015. Known Affected Releases: 15.3(3)M3. Known Fixed Releases: 15.6(2)T0.1 15.6(2.0.1a)T0 15.6(2.19)T 15.6(3)M. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 CWE-20 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-9201 Source: BID Type: Third Party Advisory, VDB Entry 94811 Source: CCN Type: BID-94811 Cisco IOS and Cisco IOS XE Software CVE-2016-9201 Security Bypass Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1037419 Source: XF Type: UNKNOWN cisco-cve20169201-sec-bypass(119546) Source: CCN Type: Cisco Security Advisory cisco-sa-20161207-ios-zbf Cisco IOS and Cisco IOS XE Software Zone-Based Firewall Feature Bypass Vulnerability Source: CONFIRM Type: Mitigation, Vendor Advisory https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ios-zbf | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |