CVE-2016-1404
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by sniffing network traffic to an Autosupport server and leveraging knowledge of this key from another installation, aka Bug ID CSCur85504.
Cisco UCS Invicta 4.3, 4.5, y 5.0.1 en los dispositivos Invicta e Invicta Scaling System usan el mismo cifrado de clave GnuPG embebido en diferentes instalaciones de clientes, lo que permite a atacantes remotos vencer los mecanismos de protección criptográfica rastreando el tráfico de red en un servidor Autosupport y aprovechando el conocimiento de esta clave proveniente de otra instalación, también conocido como Bug ID CSCur85504.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-01-04 CVE Reserved
- 2016-05-29 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1035957 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160524-ucs-inv | 2016-12-01 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Ucs Invicta C3124sa Appliance Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" | 4.3.1 Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" and version "4.3.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ucs Invicta C3124sa Appliance Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" | 4.3_base Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" and version "4.3_base" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ucs Invicta C3124sa Appliance Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" | 4.5.0 Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" and version "4.5.0" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ucs Invicta C3124sa Appliance Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" | 4.5_base Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" and version "4.5_base" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ucs Invicta C3124sa Appliance Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" | 5.0.1 Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" and version "5.0.1" | - |
Affected
| ||||||
Cisco Search vendor "Cisco" | Ucs Invicta C3124sa Appliance Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" | 5.0_base Search vendor "Cisco" for product "Ucs Invicta C3124sa Appliance" and version "5.0_base" | - |
Affected
|