Vulnerability Details CVE-2016-1420
The installation component on Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCuz72347.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.0%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2016-1420
-
cpe:2.3:h:cisco:application_infrastructure_controller:-
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(1e)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(1h)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(1k)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(1n)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(2j)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(2m)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(3f)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(3i)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(3k)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(3n)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(4h)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.0(4o)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.1(0.920a)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.1(1j)
-
cpe:2.3:o:cisco:application_policy_infrastructure_controller_firmware:1.1(3f)