Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Vulnerability in Linux Kernel Affecting Cisco Products: October 2016

cisco-sa-20161026-linux · Medium · Published · Updated

On October 19, 2016, a new vulnerability related to a race condition in the memory manager of the Linux Kernel was disclosed. This vulnerability could allow unprivileged, local users to gain write access to otherwise read-only memory mappings to increase their privileges on the system. Cisco has released software updates that address this vulnerability. For information about affected and fixed software releases, consult the Cisco bug IDs in the Vulnerable Products table. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161026-linux

Cisco advisory · CSAF JSON

Workarounds

Any available workarounds are documented in the Cisco bugs for each affected product, which are given in the Vulnerable Products table and also accessible from the Cisco Bug Search Tool ["https://bst.cloudapps.cisco.com/bugsearch/bug/BUGID"].

CVEsCVE-2016-5195
Cisco Bug IDsCSCvb85490, CSCvb85516, CSCvb85528, CSCvb85529, CSCvb85547, CSCvb85559, CSCvb85564, CSCvb85571, CSCvb85583, CSCvb85587, CSCvb85595, CSCvb85606, CSCvb85607, CSCvb85609, CSCvb85616, CSCvb85633, CSCvb85647, CSCvb85649, CSCvb85679, CSCvb85713, CSCvb85719, CSCvb85723, CSCvb85725, CSCvb87054, CSCvb96355
CVSS ScoreBase 6.9
Base 6.9 AV:L/AC:M/Au:N/C:C/I:C/A:C/E:POC/RL:W/RC:C
Product Names From Source
Cisco Prime Access Registrar, Cisco IP Interoperability and Collaboration System (IPICS), Cisco Video Surveillance Media Server Software, Cisco Digital Media Player Software, Cisco Mobility Services Engine, Cisco TelePresence Video Communication Server (VCS), Cisco Prime Data Center Network Manager (DCNM), Cisco ATA 187 Analog Telephone Adaptor, Cisco WebEx Meetings Server, Cisco MXE 3500 (Media Experience Engine), Cisco UCS Director, Cisco Videoscape Distribution Suite Transparent Caching (VDS TC), Cisco Digital Content Manager (DCM) Software, Cisco Prime Service Catalog, Cisco Application Policy Infrastructure Controller (APIC), Cisco Expressway, Cisco Jabber Guest, Cisco Visual Quality Experience, Cisco onePK All-in-One Virtual Machine, Cisco Prime Collaboration Provisioning, Cisco Prime Network, Cisco DX Series IP Phones, Cisco Paging Server, Cisco SPA112 2-Port Phone Adapter, Cisco SPA122 ATA with Router, Cisco SPA232D Multi-Line DECT ATA, Cisco Videoscape Distribution Suite Service Manager, Cisco Policy Suite (CPS) Software

Related Products

Product CVE Evidence
Cisco onePK All-in-One Virtual Machine CVE-2016-5195 Cisco OpenVuln
Cisco Webex Meetings CVE-2016-5195 Cisco OpenVuln
Cisco WebEx Meetings Server CVE-2016-5195 Cisco OpenVuln
Cisco Visual Quality Experience CVE-2016-5195 Cisco OpenVuln
Cisco Videoscape Distribution Suite Transparent Caching (VDS TC) CVE-2016-5195 Cisco OpenVuln
Cisco Videoscape Distribution Suite Service Manager CVE-2016-5195 Cisco OpenVuln
Cisco Video Surveillance Media Server Software CVE-2016-5195 Cisco OpenVuln
Cisco UCS Director CVE-2016-5195 Cisco OpenVuln
Cisco TelePresence Video Communication Server (VCS) CVE-2016-5195 Cisco OpenVuln
Cisco TelePresence CVE-2016-5195 Cisco OpenVuln
Cisco SPA232D Multi-Line DECT ATA CVE-2016-5195 Cisco OpenVuln
Cisco SPA122 ATA with Router CVE-2016-5195 Cisco OpenVuln
Cisco SPA112 2-Port Phone Adapter CVE-2016-5195 Cisco OpenVuln
Cisco Prime Service Catalog CVE-2016-5195 Cisco OpenVuln
Cisco Prime Network CVE-2016-5195 Cisco OpenVuln
Cisco Prime Data Center Network Manager (DCNM) CVE-2016-5195 Cisco OpenVuln
Cisco Prime Collaboration Provisioning CVE-2016-5195 Cisco OpenVuln
Cisco Prime Collaboration CVE-2016-5195 Cisco OpenVuln
Cisco Prime Access Registrar CVE-2016-5195 Cisco OpenVuln
Cisco Policy Suite (CPS) Software CVE-2016-5195 Cisco OpenVuln
Cisco Paging Server CVE-2016-5195 Cisco OpenVuln
Cisco Mobility Services Engine CVE-2016-5195 Cisco OpenVuln
Cisco MXE 3500 (Media Experience Engine) CVE-2016-5195 Cisco OpenVuln
Cisco Jabber Guest CVE-2016-5195 Cisco OpenVuln
Cisco Jabber CVE-2016-5195 Cisco OpenVuln
Cisco IP Interoperability and Collaboration System (IPICS) CVE-2016-5195 Cisco OpenVuln
Cisco Expressway CVE-2016-5195 Cisco OpenVuln
Cisco Digital Media Player Software CVE-2016-5195 Cisco OpenVuln
Cisco Digital Content Manager (DCM) Software CVE-2016-5195 Cisco OpenVuln
Cisco DX Series IP Phones CVE-2016-5195 Cisco OpenVuln
Cisco Application Policy Infrastructure Controller (APIC) CVE-2016-5195 Cisco OpenVuln
Cisco ATA 187 Analog Telephone Adaptor CVE-2016-5195 Cisco OpenVuln