← Back

CVE-2016-1366

nvd nist
Published: Mar 24, 2016Modified: May 6, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

Affected (6)

Products: Cisco: Ios Xr
1 product
Ios Xr
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 5.0.0
Version 5.0.1
Version 5.2.1
Version 5.2.3
Version 5.2.4
Version 5.2.5

Related CWEs

References (4)

Timeline

No history available yet.