Cisco Security Advisories · November 2016 — Cisco Security Advisories
17 advisories 29 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2016-11. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

Advisories

cisco-sa-20161123-ntpd

Cisco PSIRT2016-11-23

Multiple Vulnerabilities in Network Time Protocol Daemon Affecting Cisco Products: November 2016

CVEs:CVE-2016-9311CVE-2016-9310CVE-2016-7427CVE-2016-7428CVE-2016-9312CVE-2016-7434CVE-2016-7429CVE-2016-7426CVE-2015-8138CVE-2016-7431CVE-2016-7433

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-111580 affected Cisco
CVRFPID-111803 affected Cisco
CVRFPID-111903 affected Cisco
CVRFPID-112250 affected Cisco
CVRFPID-185359 affected Cisco
CVRFPID-188426 affected Cisco
CVRFPID-188989 affected Cisco
CVRFPID-189791 affected Cisco
CVRFPID-190324 affected Cisco
CVRFPID-190474 affected Cisco
CVRFPID-190707 affected Cisco
CVRFPID-191687 affected Cisco
CVRFPID-192324 affected Cisco
CVRFPID-193469 affected Cisco
CVRFPID-194456 affected Cisco
CVRFPID-194833 affected Cisco
CVRFPID-195223 affected Cisco
CVRFPID-195235 affected Cisco
CVRFPID-197112 affected Cisco
CVRFPID-197592 affected Cisco
CVRFPID-197708 affected Cisco
CVRFPID-198393 affected Cisco
CVRFPID-202401 affected Cisco
CVRFPID-202532 affected Cisco
CVRFPID-202553 affected Cisco
CVRFPID-202683 affected Cisco
CVRFPID-203403 affected Cisco
CVRFPID-203442 affected Cisco
CVRFPID-203607 affected Cisco
CVRFPID-203746 affected Cisco
CVRFPID-203755 affected Cisco
CVRFPID-205007 affected Cisco
CVRFPID-2054 affected Cisco
CVRFPID-209583 affected Cisco
CVRFPID-210593 affected Cisco
CVRFPID-210717 affected Cisco
CVRFPID-213561 affected Cisco
CVRFPID-213688 affected Cisco
CVRFPID-213864 affected Cisco
CVRFPID-220254 affected Cisco
CVRFPID-220301 affected Cisco
CVRFPID-225817 affected Cisco
CVRFPID-4844 affected Cisco
CVRFPID-5834 affected Cisco
CVRFPID-6046 affected Cisco
CVRFPID-73608 affected Cisco
CVRFPID-7367 affected Cisco
CVRFPID-7731 affected Cisco
CVRFPID-77997 affected Cisco
CVRFPID-8043 affected Cisco
CVRFPID-93036 affected Cisco
CVRFPID-95900 affected Cisco
CVRFPID-95918 affected Cisco
CVRFPID-96689 affected Cisco
Upstream advisory

cisco-sa-20161116-asa

Cisco PSIRT2016-11-16

Cisco ASA Input Validation File Injection Vulnerability

CVEs:CVE-2016-6461

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-202938 affected Cisco
CVRFPID-202940 affected Cisco
CVRFPID-202944 affected Cisco
CVRFPID-202945 affected Cisco
CVRFPID-202946 affected Cisco
CVRFPID-202947 affected Cisco
CVRFPID-202948 affected Cisco
CVRFPID-202949 affected Cisco
CVRFPID-204544 affected Cisco
CVRFPID-206486 affected Cisco
CVRFPID-206487 affected Cisco
CVRFPID-206488 affected Cisco
CVRFPID-206489 affected Cisco
CVRFPID-206490 affected Cisco
CVRFPID-207900 affected Cisco
CVRFPID-207903 affected Cisco
CVRFPID-207904 affected Cisco
CVRFPID-207905 affected Cisco
CVRFPID-208301 affected Cisco
CVRFPID-210984 affected Cisco
CVRFPID-210985 affected Cisco
CVRFPID-210986 affected Cisco
CVRFPID-211050 affected Cisco
CVRFPID-211054 affected Cisco
CVRFPID-211055 affected Cisco
CVRFPID-211056 affected Cisco
CVRFPID-211057 affected Cisco
CVRFPID-211058 affected Cisco
CVRFPID-211059 affected Cisco
CVRFPID-212614 affected Cisco
CVRFPID-212704 affected Cisco
CVRFPID-212705 affected Cisco
CVRFPID-212706 affected Cisco
CVRFPID-212707 affected Cisco
CVRFPID-212708 affected Cisco
CVRFPID-220448 affected Cisco
CVRFPID-220996 affected Cisco
CVRFPID-220997 affected Cisco
CVRFPID-220998 affected Cisco
CVRFPID-220999 affected Cisco
CVRFPID-221000 affected Cisco
CVRFPID-221001 affected Cisco
CVRFPID-221002 affected Cisco
CVRFPID-221003 affected Cisco
CVRFPID-221004 affected Cisco
CVRFPID-221005 affected Cisco
CVRFPID-221006 affected Cisco
CVRFPID-221007 affected Cisco
CVRFPID-221008 affected Cisco
CVRFPID-221009 affected Cisco
CVRFPID-221010 affected Cisco
CVRFPID-221011 affected Cisco
CVRFPID-221012 affected Cisco
CVRFPID-221013 affected Cisco
CVRFPID-221014 affected Cisco
CVRFPID-221015 affected Cisco
CVRFPID-221016 affected Cisco
CVRFPID-221017 affected Cisco
CVRFPID-221018 affected Cisco
CVRFPID-221019 affected Cisco
CVRFPID-221020 affected Cisco
Upstream advisory

cisco-sa-20161116-asr

Cisco PSIRT2016-11-16

Cisco ASR 5000 Series ipsecmgr Service Denial of Service Vulnerability

CVEs:CVE-2016-6466

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-193199 affected Cisco
CVRFPID-217771 affected Cisco
Upstream advisory

cisco-sa-20161116-ucm

Cisco PSIRT2016-11-16

Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability

CVEs:CVE-2016-6472

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-20161115-iosxe

Cisco PSIRTHIGH2016-11-15

Cisco IOS XE Software Directory Traversal Vulnerability

CVEs:CVE-2016-6450

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-196216 affected Cisco
CVRFPID-196218 affected Cisco
CVRFPID-196221 affected Cisco
CVRFPID-196222 affected Cisco
CVRFPID-196223 affected Cisco
CVRFPID-196925 affected Cisco
CVRFPID-197145 affected Cisco
CVRFPID-206168 affected Cisco
CVRFPID-206169 affected Cisco
CVRFPID-206170 affected Cisco
CVRFPID-206172 affected Cisco
CVRFPID-206173 affected Cisco
CVRFPID-206200 affected Cisco
CVRFPID-206201 affected Cisco
CVRFPID-206202 affected Cisco
CVRFPID-206203 affected Cisco
CVRFPID-206211 affected Cisco
CVRFPID-210073 affected Cisco
CVRFPID-210074 affected Cisco
CVRFPID-210075 affected Cisco
CVRFPID-210076 affected Cisco
CVRFPID-210077 affected Cisco
CVRFPID-210264 affected Cisco
CVRFPID-212436 affected Cisco
CVRFPID-212674 affected Cisco
CVRFPID-213100 affected Cisco
CVRFPID-213790 affected Cisco
CVRFPID-213797 affected Cisco
CVRFPID-213809 affected Cisco
CVRFPID-213811 affected Cisco
CVRFPID-213812 affected Cisco
CVRFPID-213960 affected Cisco
CVRFPID-214993 affected Cisco
CVRFPID-217253 affected Cisco
CVRFPID-217279 affected Cisco
CVRFPID-217280 affected Cisco
CVRFPID-217282 affected Cisco
CVRFPID-217283 affected Cisco
CVRFPID-220802 affected Cisco
CVRFPID-296860 affected Cisco
CVRFPID-306636 affected Cisco
Upstream advisory

cisco-sa-20161114-openssl

Cisco PSIRTHIGH2016-11-14

Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: November 2016

CVEs:CVE-2016-7054CVE-2016-7053CVE-2016-7055

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-111903 affected Cisco
CVRFPID-189791 affected Cisco
CVRFPID-190474 affected Cisco
CVRFPID-190570 affected Cisco
CVRFPID-190702 affected Cisco
CVRFPID-195936 affected Cisco
CVRFPID-197112 affected Cisco
CVRFPID-202553 affected Cisco
CVRFPID-203639 affected Cisco
CVRFPID-203724 affected Cisco
CVRFPID-203755 affected Cisco
CVRFPID-203834 affected Cisco
CVRFPID-205007 affected Cisco
CVRFPID-210536 affected Cisco
CVRFPID-210554 affected Cisco
CVRFPID-210834 affected Cisco
CVRFPID-210903 affected Cisco
CVRFPID-5834 affected Cisco
CVRFPID-5940 affected Cisco
CVRFPID-73608 affected Cisco
CVRFPID-7367 affected Cisco
CVRFPID-7368 affected Cisco
CVRFPID-7500 affected Cisco
CVRFPID-77997 affected Cisco
CVRFPID-79783 affected Cisco
CVRFPID-95900 affected Cisco
CVRFPID-96689 affected Cisco
Upstream advisory

cisco-sa-20161102-cms

Cisco PSIRT2016-11-02

Cisco Meeting Server and Meeting App Buffer Underflow Vulnerability

CVEs:CVE-2016-6447

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-217166 affected Cisco
CVRFPID-221064 affected Cisco
Upstream advisory

cisco-sa-20161102-cms1

Cisco PSIRT2016-11-02

Cisco Meeting Server Session Description Protocol Media Lines Buffer Overflow Vulnerability

CVEs:CVE-2016-6448

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-217166 affected Cisco
Upstream advisory

cisco-sa-20161102-tl1

Cisco PSIRTHIGH2016-11-02

Cisco ASR 900 Series Aggregation Services Routers Buffer Overflow Vulnerability

CVEs:CVE-2016-6441

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-211571 affected Cisco
CVRFPID-217271 affected Cisco
CVRFPID-217272 affected Cisco
CVRFPID-286799 affected Cisco
CVRFPID-286801 affected Cisco
CVRFPID-294838 affected Cisco
CVRFPID-295359 affected Cisco
CVRFPID-296763 affected Cisco
CVRFPID-300012 affected Cisco
CVRFPID-300823 affected Cisco
CVRFPID-300834 affected Cisco
CVRFPID-300936 affected Cisco
CVRFPID-300947 affected Cisco
CVRFPID-300948 affected Cisco
CVRFPID-301162 affected Cisco
CVRFPID-301254 affected Cisco
CVRFPID-301716 affected Cisco
CVRFPID-302628 affected Cisco
CVRFPID-302758 affected Cisco
CVRFPID-302964 affected Cisco
CVRFPID-303024 affected Cisco
CVRFPID-303034 affected Cisco
CVRFPID-303308 affected Cisco
CVRFPID-303324 affected Cisco
CVRFPID-303470 affected Cisco
CVRFPID-303471 affected Cisco
CVRFPID-305276 affected Cisco
CVRFPID-306389 affected Cisco
CVRFPID-306611 affected Cisco
CVRFPID-306635 affected Cisco
CVRFPID-306804 affected Cisco
CVRFPID-306815 affected Cisco
CVRFPID-306849 affected Cisco
CVRFPID-306957 affected Cisco
CVRFPID-307272 affected Cisco
CVRFPID-307313 affected Cisco
Upstream advisory

cisco-sa-20161102-tp

Cisco PSIRT2016-11-02

Cisco TelePresence Endpoints Local Command Injection Vulnerability

CVEs:CVE-2016-6459

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-192563 affected Cisco
CVRFPID-222445 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.