Cisco Security Advisories · December 2016 — Cisco Security Advisories
33 advisories 33 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2016-12. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

Advisories

cisco-sa-20161207-asyncos

Cisco PSIRT2016-12-07

Cisco Security Appliances AsyncOS Software Update Server Certificate Validation Vulnerability

CVEs:CVE-2016-1411

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189789 affected Cisco
CVRFPID-189790 affected Cisco
CVRFPID-189791 affected Cisco
Upstream advisory

cisco-sa-20161207-cons

Cisco PSIRT2016-12-07

Cisco ONS 15454 Series Multiservice Provisioning Platforms TCP Port Management Denial of Service Vulnerability

CVEs:CVE-2016-9211

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-87908 affected Cisco
Upstream advisory

cisco-sa-20161207-cucm

Cisco PSIRT2016-12-07

Cisco Unified Communications Manager Administration Page Cross-Site Scripting Vulnerability

CVEs:CVE-2016-9206

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-20161207-cur

Cisco PSIRT2016-12-07

Cisco Unified Communications Manager Unified Reporting Upload Tool Directory Traversal Vulnerability

CVEs:CVE-2016-9210

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-20161207-esa

Cisco PSIRT2016-12-07

Cisco Email Security Appliance Content Filter Bypass Vulnerability

CVEs:CVE-2016-6465

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189789 affected Cisco
CVRFPID-189790 affected Cisco
Upstream advisory

cisco-sa-20161207-firepower

Cisco PSIRT2016-12-07

Cisco Firepower Management Center and Cisco FireSIGHT System Software Malicious Software Detection Bypass Vulnerability

CVEs:CVE-2016-9193

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-205007 affected Cisco
CVRFPID-212171 affected Cisco
CVRFPID-212172 affected Cisco
CVRFPID-213676 affected Cisco
CVRFPID-213754 affected Cisco
CVRFPID-216309 affected Cisco
CVRFPID-222771 affected Cisco
Upstream advisory

cisco-sa-20161207-fpwr

Cisco PSIRT2016-12-07

Cisco FirePOWER Malware Protection Bypass Vulnerability

CVEs:CVE-2016-9209

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-220205 affected Cisco
CVRFPID-220206 affected Cisco
CVRFPID-220207 affected Cisco
CVRFPID-223029 affected Cisco
CVRFPID-223031 affected Cisco
CVRFPID-223033 affected Cisco
Upstream advisory

cisco-sa-20161207-ios-xr

Cisco PSIRT2016-12-07

Cisco IOS XR Software HTTP 2.0 Request Handling Event Service Daemon Denial of Service Vulnerability

CVEs:CVE-2016-9205

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-5834 affected Cisco
Upstream advisory

cisco-sa-20161207-ise

Cisco PSIRT2016-12-07

Cisco Identity Services Engine Active Directory Integration Component Denial of Service Vulnerability

CVEs:CVE-2016-9198

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-111903 affected Cisco
Upstream advisory

cisco-sa-20161207-ucm

Cisco PSIRT2016-12-07

Cisco Unified Communications Manager IM and Presence Service Information Disclosure Vulnerability

CVEs:CVE-2016-6464

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-189784 affected Cisco
Upstream advisory

cisco-sa-20161207-vdc

Cisco PSIRT2016-12-07

Cisco Firepower Management Center Information Disclosure Vulnerability

CVEs:CVE-2016-6471

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-205007 affected Cisco
CVRFPID-212162 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.