Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco Configuration Assistant Request Processing Unauthorized Access Vulnerability

cisco-sa-20160630-cca · Medium · Published · Updated

A vulnerability in Cisco Configuration Assistant (CCA) could allow an unauthenticated, remote attacker to access sensitive file systems and administrative endpoints without user authentication. The vulnerability is due to lack of controller mechanisms and input validation checks. An attacker could exploit this vulnerability by running GET queries to the administrative endpoints of the Cloud Network Automation Provisioner (CNAP) Application Programming Interface (API), providing access to other administrative controllers that do not utilize authentication or authorization-checking mechanisms. Cisco has not released software updates that address this vulnerability. Workarounds that mitigate this vulnerability are not available. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160630-cca

Cisco advisory · CSAF JSON

Workarounds

Workarounds are not available.

CVEsCVE-2016-1441
Cisco Bug IDsCSCuy77145
CVSS ScoreBase 5.8
Base 5.8 AV:N/AC:M/Au:N/C:P/I:P/A:N/E:F/RL:U/RC:C
Product Names From Source
Cisco Cloud Network Automation Provisioner

Related Products

Product CVE Evidence
Cisco Configuration Assistant (CCA) CVE-2016-1441 Cisco OpenVuln
Cisco Cloud Network Automation Provisioner CVE-2016-1441 Cisco OpenVuln