Cisco Security Advisories · June 2016 — Cisco Security Advisories
33 advisories 37 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2016-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

Advisories

cisco-sa-20160630-cca

Cisco PSIRT2016-06-30

Cisco Configuration Assistant Request Processing Unauthorized Access Vulnerability

CVEs:CVE-2016-1441

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-215018 affected Cisco
Upstream advisory

cisco-sa-20160629-pi-epnm

Cisco PSIRT2016-06-29

Cisco Prime Infrastructure and Evolved Programmable Network Manager Authenticated Remote Code Execution Vulnerability

CVEs:CVE-2016-1408

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

cisco-sa-20160629-piauthbypass

Cisco PSIRT2016-06-29

Cisco Prime Infrastructure and Evolved Programmable Network Manager Authentication Bypass API Vulnerability

CVEs:CVE-2016-1289

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

cisco-sa-20160622-ucce

Cisco PSIRT2016-06-22

Cisco Unified Contact Center Enterprise Web-Based Management Interface Cross-Site Scripting Vulnerability

CVEs:CVE-2016-1439

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-7500 affected Cisco
Upstream advisory

cisco-sa-20160621-asr

Cisco PSIRT2016-06-21

Cisco ASR 5000 Series Packet Data Network Gateway Denial of Service Vulnerability

CVEs:CVE-2016-1436

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-193199 affected Cisco
Upstream advisory

cisco-sa-20160620-iosxe

Cisco PSIRT2016-06-20

Cisco IOS XE Software SNMP Subsystem Denial of Service Vulnerability

CVEs:CVE-2016-1428

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-206180 affected Cisco
CVRFPID-210081 affected Cisco
CVRFPID-212411 affected Cisco
Upstream advisory

cisco-sa-20160620-ipp

Cisco PSIRT2016-06-20

Cisco 8800 Series IP Phone Filesystem Permission Enforcement Unauthorized Access Vulnerability

CVEs:CVE-2016-1435

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-205455 affected Cisco
Upstream advisory

cisco-sa-20160617-cbr

Cisco PSIRT2016-06-17

Cisco cBR-8 Series Converged Broadband Router SNMP Denial of Service Vulnerability

CVEs:CVE-2016-1432

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-206180 affected Cisco
CVRFPID-210079 affected Cisco
CVRFPID-210081 affected Cisco
Upstream advisory

cisco-sa-20160617-fmc

Cisco PSIRT2016-06-17

Cisco Firepower Management Center Persistent Cross-Site Scripting Vulnerability

CVEs:CVE-2016-1431

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-213668 affected Cisco
CVRFPID-216729 affected Cisco
CVRFPID-216730 affected Cisco
CVRFPID-216733 affected Cisco
CVRFPID-216736 affected Cisco
Upstream advisory

cisco-sa-20160616-ios

Cisco PSIRT2016-06-17

Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability

CVEs:CVE-2016-1424

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-2097 affected Cisco
Upstream advisory

cisco-sa-20160616-ios1

Cisco PSIRT2016-06-17

Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability

CVEs:CVE-2016-1425

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-2097 affected Cisco
Upstream advisory

cisco-sa-20160616-pnr

Cisco PSIRT2016-06-16

Cisco Prime Network Registrar System Configuration Protocol Information Disclosure Vulnerability

CVEs:CVE-2016-1427

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-195936 affected Cisco
Upstream advisory

cisco-sa-20160615-rv

Cisco PSIRT2016-06-15

Cisco RV110W, RV130W, and RV215W Routers Arbitrary Code Execution Vulnerability

CVEs:CVE-2016-1395

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-212336 affected Cisco
CVRFPID-212341 affected Cisco
CVRFPID-212498 affected Cisco
Upstream advisory

cisco-sa-20160615-rv1

Cisco PSIRT2016-06-15

Cisco RV110W, RV130W, and RV215W Routers Cross-Site Scripting Vulnerability

CVEs:CVE-2016-1396

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-212336 affected Cisco
CVRFPID-212341 affected Cisco
CVRFPID-212498 affected Cisco
Upstream advisory

cisco-sa-20160615-rv2

Cisco PSIRT2016-06-15

Cisco RV110W, RV130W, and RV215W Routers HTTP Request Buffer Overflow Vulnerability

CVEs:CVE-2016-1397

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-212336 affected Cisco
CVRFPID-212341 affected Cisco
CVRFPID-212498 affected Cisco
Upstream advisory

cisco-sa-20160615-rv3

Cisco PSIRT2016-06-15

Cisco RV110W, RV130W, and RV215W Routers HTTP Request Buffer Overflow Vulnerability

CVEs:CVE-2016-1398

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-212336 affected Cisco
CVRFPID-212341 affected Cisco
CVRFPID-212498 affected Cisco
Upstream advisory

cisco-sa-20160609-ipp

Cisco PSIRTHIGH2016-06-09

Cisco IP Phones Web Application Buffer Overflow Vulnerability

CVEs:CVE-2016-1421

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-205455 affected Cisco
CVRFPID-4473 affected Cisco
Upstream advisory

cisco-sa-20160608-aironet

Cisco PSIRT2016-06-09

Cisco Aironet 1800, 2800, and 3800 Series Access Point Platforms ARP Request Handling Denial of Service Vulnerability

CVEs:CVE-2016-1419

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190024 affected Cisco
Upstream advisory

cisco-sa-20160609-apic

Cisco PSIRT2016-06-09

Cisco Application Policy Infrastructure Controller Binary Files Privilege Escalation Vulnerability

CVEs:CVE-2016-1420

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-202553 affected Cisco
Upstream advisory

cisco-sa-20160606-aap

Cisco PSIRT2016-06-06

Cisco Aironet Access Points Command-Line Interpreter Linux Shell Command Injection Vulnerability

CVEs:CVE-2016-1418

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190024 affected Cisco
Upstream advisory

cisco-sa-20160603-ntpd

Cisco PSIRT2016-06-03

Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: June 2016

CVEs:CVE-2016-4957CVE-2016-4953CVE-2016-4954CVE-2016-4955CVE-2016-4956

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-111580 affected Cisco
CVRFPID-111903 affected Cisco
CVRFPID-112250 affected Cisco
CVRFPID-184512 affected Cisco
CVRFPID-184690 affected Cisco
CVRFPID-185359 affected Cisco
CVRFPID-188426 affected Cisco
CVRFPID-188989 affected Cisco
CVRFPID-190324 affected Cisco
CVRFPID-190474 affected Cisco
CVRFPID-190702 affected Cisco
CVRFPID-190707 affected Cisco
CVRFPID-191687 affected Cisco
CVRFPID-192324 affected Cisco
CVRFPID-192775 affected Cisco
CVRFPID-194833 affected Cisco
CVRFPID-195223 affected Cisco
CVRFPID-197112 affected Cisco
CVRFPID-197592 affected Cisco
CVRFPID-197708 affected Cisco
CVRFPID-202401 affected Cisco
CVRFPID-202532 affected Cisco
CVRFPID-202553 affected Cisco
CVRFPID-202683 affected Cisco
CVRFPID-203403 affected Cisco
CVRFPID-203442 affected Cisco
CVRFPID-203607 affected Cisco
CVRFPID-203731 affected Cisco
CVRFPID-203737 affected Cisco
CVRFPID-203746 affected Cisco
CVRFPID-203755 affected Cisco
CVRFPID-205007 affected Cisco
CVRFPID-2054 affected Cisco
CVRFPID-209582 affected Cisco
CVRFPID-209583 affected Cisco
CVRFPID-210717 affected Cisco
CVRFPID-210844 affected Cisco
CVRFPID-210903 affected Cisco
CVRFPID-211903 affected Cisco
CVRFPID-213561 affected Cisco
CVRFPID-213864 affected Cisco
CVRFPID-220254 affected Cisco
CVRFPID-220301 affected Cisco
CVRFPID-225817 affected Cisco
CVRFPID-4844 affected Cisco
CVRFPID-5834 affected Cisco
CVRFPID-6046 affected Cisco
CVRFPID-6407 affected Cisco
CVRFPID-6439 affected Cisco
CVRFPID-73608 affected Cisco
CVRFPID-7365 affected Cisco
CVRFPID-7367 affected Cisco
CVRFPID-7731 affected Cisco
CVRFPID-77997 affected Cisco
CVRFPID-8043 affected Cisco
CVRFPID-92399 affected Cisco
CVRFPID-93036 affected Cisco
CVRFPID-95900 affected Cisco
CVRFPID-95918 affected Cisco
CVRFPID-96689 affected Cisco
CVRFPID-96780 affected Cisco
CVRFPID-99257 affected Cisco
Upstream advisory

cisco-sa-20160601-prime

Cisco PSIRT2016-06-01

Cisco Prime Network Analysis Module Unauthenticated Remote Code Execution Vulnerability

CVEs:CVE-2016-1388

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-214901 affected Cisco
CVRFPID-214917 affected Cisco
Upstream advisory

cisco-sa-20160601-prime1

Cisco PSIRT2016-06-01

Cisco Prime Network Analysis Module Local Command Injection Vulnerability

CVEs:CVE-2016-1390

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-214901 affected Cisco
CVRFPID-214917 affected Cisco
Upstream advisory

cisco-sa-20160601-prime2

Cisco PSIRT2016-06-01

Cisco Prime Network Analysis Module Authenticated Remote Code Execution Vulnerability

CVEs:CVE-2016-1391

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-214901 affected Cisco
CVRFPID-214917 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.