Advisories
Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016
CVEs:CVE-2016-9311CVE-2016-9310CVE-2016-7427CVE-2016-7428CVE-2016-9312CVE-2016-7434CVE-2016-7429CVE-2016-7426CVE-2015-8138CVE-2016-7431CVE-2016-7433
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-111580 |
affected |
Cisco |
— |
— |
| CVRFPID-111803 |
affected |
Cisco |
— |
— |
| CVRFPID-111903 |
affected |
Cisco |
— |
— |
| CVRFPID-112250 |
affected |
Cisco |
— |
— |
| CVRFPID-185359 |
affected |
Cisco |
— |
— |
| CVRFPID-188426 |
affected |
Cisco |
— |
— |
| CVRFPID-188989 |
affected |
Cisco |
— |
— |
| CVRFPID-189791 |
affected |
Cisco |
— |
— |
| CVRFPID-190324 |
affected |
Cisco |
— |
— |
| CVRFPID-190474 |
affected |
Cisco |
— |
— |
| CVRFPID-190707 |
affected |
Cisco |
— |
— |
| CVRFPID-191687 |
affected |
Cisco |
— |
— |
| CVRFPID-192324 |
affected |
Cisco |
— |
— |
| CVRFPID-193469 |
affected |
Cisco |
— |
— |
| CVRFPID-194456 |
affected |
Cisco |
— |
— |
| CVRFPID-194833 |
affected |
Cisco |
— |
— |
| CVRFPID-195223 |
affected |
Cisco |
— |
— |
| CVRFPID-195235 |
affected |
Cisco |
— |
— |
| CVRFPID-197112 |
affected |
Cisco |
— |
— |
| CVRFPID-197592 |
affected |
Cisco |
— |
— |
| CVRFPID-197708 |
affected |
Cisco |
— |
— |
| CVRFPID-198393 |
affected |
Cisco |
— |
— |
| CVRFPID-202401 |
affected |
Cisco |
— |
— |
| CVRFPID-202532 |
affected |
Cisco |
— |
— |
| CVRFPID-202553 |
affected |
Cisco |
— |
— |
| CVRFPID-202683 |
affected |
Cisco |
— |
— |
| CVRFPID-203403 |
affected |
Cisco |
— |
— |
| CVRFPID-203442 |
affected |
Cisco |
— |
— |
| CVRFPID-203607 |
affected |
Cisco |
— |
— |
| CVRFPID-203746 |
affected |
Cisco |
— |
— |
| CVRFPID-203755 |
affected |
Cisco |
— |
— |
| CVRFPID-205007 |
affected |
Cisco |
— |
— |
| CVRFPID-2054 |
affected |
Cisco |
— |
— |
| CVRFPID-209583 |
affected |
Cisco |
— |
— |
| CVRFPID-210593 |
affected |
Cisco |
— |
— |
| CVRFPID-210717 |
affected |
Cisco |
— |
— |
| CVRFPID-213561 |
affected |
Cisco |
— |
— |
| CVRFPID-213688 |
affected |
Cisco |
— |
— |
| CVRFPID-213864 |
affected |
Cisco |
— |
— |
| CVRFPID-220254 |
affected |
Cisco |
— |
— |
| CVRFPID-220301 |
affected |
Cisco |
— |
— |
| CVRFPID-225817 |
affected |
Cisco |
— |
— |
| CVRFPID-4844 |
affected |
Cisco |
— |
— |
| CVRFPID-5834 |
affected |
Cisco |
— |
— |
| CVRFPID-6046 |
affected |
Cisco |
— |
— |
| CVRFPID-73608 |
affected |
Cisco |
— |
— |
| CVRFPID-7367 |
affected |
Cisco |
— |
— |
| CVRFPID-7731 |
affected |
Cisco |
— |
— |
| CVRFPID-77997 |
affected |
Cisco |
— |
— |
| CVRFPID-8043 |
affected |
Cisco |
— |
— |
| CVRFPID-93036 |
affected |
Cisco |
— |
— |
| CVRFPID-95900 |
affected |
Cisco |
— |
— |
| CVRFPID-95918 |
affected |
Cisco |
— |
— |
| CVRFPID-96689 |
affected |
Cisco |
— |
— |
Cisco ASA Input Validation File Injection Vulnerability
CVEs:CVE-2016-6461
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-202938 |
affected |
Cisco |
— |
— |
| CVRFPID-202940 |
affected |
Cisco |
— |
— |
| CVRFPID-202944 |
affected |
Cisco |
— |
— |
| CVRFPID-202945 |
affected |
Cisco |
— |
— |
| CVRFPID-202946 |
affected |
Cisco |
— |
— |
| CVRFPID-202947 |
affected |
Cisco |
— |
— |
| CVRFPID-202948 |
affected |
Cisco |
— |
— |
| CVRFPID-202949 |
affected |
Cisco |
— |
— |
| CVRFPID-204544 |
affected |
Cisco |
— |
— |
| CVRFPID-206486 |
affected |
Cisco |
— |
— |
| CVRFPID-206487 |
affected |
Cisco |
— |
— |
| CVRFPID-206488 |
affected |
Cisco |
— |
— |
| CVRFPID-206489 |
affected |
Cisco |
— |
— |
| CVRFPID-206490 |
affected |
Cisco |
— |
— |
| CVRFPID-207900 |
affected |
Cisco |
— |
— |
| CVRFPID-207903 |
affected |
Cisco |
— |
— |
| CVRFPID-207904 |
affected |
Cisco |
— |
— |
| CVRFPID-207905 |
affected |
Cisco |
— |
— |
| CVRFPID-208301 |
affected |
Cisco |
— |
— |
| CVRFPID-210984 |
affected |
Cisco |
— |
— |
| CVRFPID-210985 |
affected |
Cisco |
— |
— |
| CVRFPID-210986 |
affected |
Cisco |
— |
— |
| CVRFPID-211050 |
affected |
Cisco |
— |
— |
| CVRFPID-211054 |
affected |
Cisco |
— |
— |
| CVRFPID-211055 |
affected |
Cisco |
— |
— |
| CVRFPID-211056 |
affected |
Cisco |
— |
— |
| CVRFPID-211057 |
affected |
Cisco |
— |
— |
| CVRFPID-211058 |
affected |
Cisco |
— |
— |
| CVRFPID-211059 |
affected |
Cisco |
— |
— |
| CVRFPID-212614 |
affected |
Cisco |
— |
— |
| CVRFPID-212704 |
affected |
Cisco |
— |
— |
| CVRFPID-212705 |
affected |
Cisco |
— |
— |
| CVRFPID-212706 |
affected |
Cisco |
— |
— |
| CVRFPID-212707 |
affected |
Cisco |
— |
— |
| CVRFPID-212708 |
affected |
Cisco |
— |
— |
| CVRFPID-220448 |
affected |
Cisco |
— |
— |
| CVRFPID-220996 |
affected |
Cisco |
— |
— |
| CVRFPID-220997 |
affected |
Cisco |
— |
— |
| CVRFPID-220998 |
affected |
Cisco |
— |
— |
| CVRFPID-220999 |
affected |
Cisco |
— |
— |
| CVRFPID-221000 |
affected |
Cisco |
— |
— |
| CVRFPID-221001 |
affected |
Cisco |
— |
— |
| CVRFPID-221002 |
affected |
Cisco |
— |
— |
| CVRFPID-221003 |
affected |
Cisco |
— |
— |
| CVRFPID-221004 |
affected |
Cisco |
— |
— |
| CVRFPID-221005 |
affected |
Cisco |
— |
— |
| CVRFPID-221006 |
affected |
Cisco |
— |
— |
| CVRFPID-221007 |
affected |
Cisco |
— |
— |
| CVRFPID-221008 |
affected |
Cisco |
— |
— |
| CVRFPID-221009 |
affected |
Cisco |
— |
— |
| CVRFPID-221010 |
affected |
Cisco |
— |
— |
| CVRFPID-221011 |
affected |
Cisco |
— |
— |
| CVRFPID-221012 |
affected |
Cisco |
— |
— |
| CVRFPID-221013 |
affected |
Cisco |
— |
— |
| CVRFPID-221014 |
affected |
Cisco |
— |
— |
| CVRFPID-221015 |
affected |
Cisco |
— |
— |
| CVRFPID-221016 |
affected |
Cisco |
— |
— |
| CVRFPID-221017 |
affected |
Cisco |
— |
— |
| CVRFPID-221018 |
affected |
Cisco |
— |
— |
| CVRFPID-221019 |
affected |
Cisco |
— |
— |
| CVRFPID-221020 |
affected |
Cisco |
— |
— |
Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability
CVEs:CVE-2016-6466
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-193199 |
affected |
Cisco |
— |
— |
| CVRFPID-217771 |
affected |
Cisco |
— |
— |
Cisco Email Security Appliance MIME Header Processing Filter Bypass Vulnerability
CVEs:CVE-2016-6462
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-189790 |
affected |
Cisco |
— |
— |
Cisco Email Security Appliance MIME Header Processing Filter Bypass Vulnerability
CVEs:CVE-2016-6463
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-189790 |
affected |
Cisco |
— |
— |
Cisco Firepower System Software FTP Malware Vulnerability
CVEs:CVE-2016-6460
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-205007 |
affected |
Cisco |
— |
— |
Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
CVEs:CVE-2016-6472
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-88444 |
affected |
Cisco |
— |
— |
Cisco PSIRTHIGH2016-11-15
Cisco IOS XE Software Directory Traversal Vulnerability
CVEs:CVE-2016-6450
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-196216 |
affected |
Cisco |
— |
— |
| CVRFPID-196218 |
affected |
Cisco |
— |
— |
| CVRFPID-196221 |
affected |
Cisco |
— |
— |
| CVRFPID-196222 |
affected |
Cisco |
— |
— |
| CVRFPID-196223 |
affected |
Cisco |
— |
— |
| CVRFPID-196925 |
affected |
Cisco |
— |
— |
| CVRFPID-197145 |
affected |
Cisco |
— |
— |
| CVRFPID-206168 |
affected |
Cisco |
— |
— |
| CVRFPID-206169 |
affected |
Cisco |
— |
— |
| CVRFPID-206170 |
affected |
Cisco |
— |
— |
| CVRFPID-206172 |
affected |
Cisco |
— |
— |
| CVRFPID-206173 |
affected |
Cisco |
— |
— |
| CVRFPID-206200 |
affected |
Cisco |
— |
— |
| CVRFPID-206201 |
affected |
Cisco |
— |
— |
| CVRFPID-206202 |
affected |
Cisco |
— |
— |
| CVRFPID-206203 |
affected |
Cisco |
— |
— |
| CVRFPID-206211 |
affected |
Cisco |
— |
— |
| CVRFPID-210073 |
affected |
Cisco |
— |
— |
| CVRFPID-210074 |
affected |
Cisco |
— |
— |
| CVRFPID-210075 |
affected |
Cisco |
— |
— |
| CVRFPID-210076 |
affected |
Cisco |
— |
— |
| CVRFPID-210077 |
affected |
Cisco |
— |
— |
| CVRFPID-210264 |
affected |
Cisco |
— |
— |
| CVRFPID-212436 |
affected |
Cisco |
— |
— |
| CVRFPID-212674 |
affected |
Cisco |
— |
— |
| CVRFPID-213100 |
affected |
Cisco |
— |
— |
| CVRFPID-213790 |
affected |
Cisco |
— |
— |
| CVRFPID-213797 |
affected |
Cisco |
— |
— |
| CVRFPID-213809 |
affected |
Cisco |
— |
— |
| CVRFPID-213811 |
affected |
Cisco |
— |
— |
| CVRFPID-213812 |
affected |
Cisco |
— |
— |
| CVRFPID-213960 |
affected |
Cisco |
— |
— |
| CVRFPID-214993 |
affected |
Cisco |
— |
— |
| CVRFPID-217253 |
affected |
Cisco |
— |
— |
| CVRFPID-217279 |
affected |
Cisco |
— |
— |
| CVRFPID-217280 |
affected |
Cisco |
— |
— |
| CVRFPID-217282 |
affected |
Cisco |
— |
— |
| CVRFPID-217283 |
affected |
Cisco |
— |
— |
| CVRFPID-220802 |
affected |
Cisco |
— |
— |
| CVRFPID-296860 |
affected |
Cisco |
— |
— |
| CVRFPID-306636 |
affected |
Cisco |
— |
— |
Cisco PSIRTHIGH2016-11-14
Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016
CVEs:CVE-2016-7054CVE-2016-7053CVE-2016-7055
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-111903 |
affected |
Cisco |
— |
— |
| CVRFPID-189791 |
affected |
Cisco |
— |
— |
| CVRFPID-190474 |
affected |
Cisco |
— |
— |
| CVRFPID-190570 |
affected |
Cisco |
— |
— |
| CVRFPID-190702 |
affected |
Cisco |
— |
— |
| CVRFPID-195936 |
affected |
Cisco |
— |
— |
| CVRFPID-197112 |
affected |
Cisco |
— |
— |
| CVRFPID-202553 |
affected |
Cisco |
— |
— |
| CVRFPID-203639 |
affected |
Cisco |
— |
— |
| CVRFPID-203724 |
affected |
Cisco |
— |
— |
| CVRFPID-203755 |
affected |
Cisco |
— |
— |
| CVRFPID-203834 |
affected |
Cisco |
— |
— |
| CVRFPID-205007 |
affected |
Cisco |
— |
— |
| CVRFPID-210536 |
affected |
Cisco |
— |
— |
| CVRFPID-210554 |
affected |
Cisco |
— |
— |
| CVRFPID-210834 |
affected |
Cisco |
— |
— |
| CVRFPID-210903 |
affected |
Cisco |
— |
— |
| CVRFPID-5834 |
affected |
Cisco |
— |
— |
| CVRFPID-5940 |
affected |
Cisco |
— |
— |
| CVRFPID-73608 |
affected |
Cisco |
— |
— |
| CVRFPID-7367 |
affected |
Cisco |
— |
— |
| CVRFPID-7368 |
affected |
Cisco |
— |
— |
| CVRFPID-7500 |
affected |
Cisco |
— |
— |
| CVRFPID-77997 |
affected |
Cisco |
— |
— |
| CVRFPID-79783 |
affected |
Cisco |
— |
— |
| CVRFPID-95900 |
affected |
Cisco |
— |
— |
| CVRFPID-96689 |
affected |
Cisco |
— |
— |
Cisco ASR 5500 Series with DPC2 Cards SESSMGR Denial of Service Vulnerability
CVEs:CVE-2016-6455
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-193199 |
affected |
Cisco |
— |
— |
Cisco Meeting Server and Meeting App Buffer Underflow Vulnerability
CVEs:CVE-2016-6447
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-217166 |
affected |
Cisco |
— |
— |
| CVRFPID-221064 |
affected |
Cisco |
— |
— |
Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability
CVEs:CVE-2016-6448
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-217166 |
affected |
Cisco |
— |
— |
Cisco Prime Home Authentication Bypass Vulnerability
CVEs:CVE-2016-6452
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-220486 |
affected |
Cisco |
— |
— |
Cisco Email Security Appliance RAR File Attachment Scanner Bypass Vulnerability
CVEs:CVE-2016-6458
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-189790 |
affected |
Cisco |
— |
— |
Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability
CVEs:CVE-2016-6457
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-202553 |
affected |
Cisco |
— |
— |
Cisco PSIRTHIGH2016-11-02
Cisco ASR 900 Series Aggregation Services Routers Buffer Overflow Vulnerability
CVEs:CVE-2016-6441
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-211571 |
affected |
Cisco |
— |
— |
| CVRFPID-217271 |
affected |
Cisco |
— |
— |
| CVRFPID-217272 |
affected |
Cisco |
— |
— |
| CVRFPID-286799 |
affected |
Cisco |
— |
— |
| CVRFPID-286801 |
affected |
Cisco |
— |
— |
| CVRFPID-294838 |
affected |
Cisco |
— |
— |
| CVRFPID-295359 |
affected |
Cisco |
— |
— |
| CVRFPID-296763 |
affected |
Cisco |
— |
— |
| CVRFPID-300012 |
affected |
Cisco |
— |
— |
| CVRFPID-300823 |
affected |
Cisco |
— |
— |
| CVRFPID-300834 |
affected |
Cisco |
— |
— |
| CVRFPID-300936 |
affected |
Cisco |
— |
— |
| CVRFPID-300947 |
affected |
Cisco |
— |
— |
| CVRFPID-300948 |
affected |
Cisco |
— |
— |
| CVRFPID-301162 |
affected |
Cisco |
— |
— |
| CVRFPID-301254 |
affected |
Cisco |
— |
— |
| CVRFPID-301716 |
affected |
Cisco |
— |
— |
| CVRFPID-302628 |
affected |
Cisco |
— |
— |
| CVRFPID-302758 |
affected |
Cisco |
— |
— |
| CVRFPID-302964 |
affected |
Cisco |
— |
— |
| CVRFPID-303024 |
affected |
Cisco |
— |
— |
| CVRFPID-303034 |
affected |
Cisco |
— |
— |
| CVRFPID-303308 |
affected |
Cisco |
— |
— |
| CVRFPID-303324 |
affected |
Cisco |
— |
— |
| CVRFPID-303470 |
affected |
Cisco |
— |
— |
| CVRFPID-303471 |
affected |
Cisco |
— |
— |
| CVRFPID-305276 |
affected |
Cisco |
— |
— |
| CVRFPID-306389 |
affected |
Cisco |
— |
— |
| CVRFPID-306611 |
affected |
Cisco |
— |
— |
| CVRFPID-306635 |
affected |
Cisco |
— |
— |
| CVRFPID-306804 |
affected |
Cisco |
— |
— |
| CVRFPID-306815 |
affected |
Cisco |
— |
— |
| CVRFPID-306849 |
affected |
Cisco |
— |
— |
| CVRFPID-306957 |
affected |
Cisco |
— |
— |
| CVRFPID-307272 |
affected |
Cisco |
— |
— |
| CVRFPID-307313 |
affected |
Cisco |
— |
— |
Cisco TelePresence Endpoints Local Command Injection Vulnerability
CVEs:CVE-2016-6459
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-192563 |
affected |
Cisco |
— |
— |
| CVRFPID-222445 |
affected |
Cisco |
— |
— |