CVE-2016-6457
Last modified
CVE-2016-6457 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). EPSS estimates a 0.72% chance of exploitation in the next 30 days.
Description
A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). More Information: CSCuy93241. Known Affected Releases: 11.2(2x) 11.2(3x) 11.3(1x) 11.3(2x) 12.0(1x). Known Fixed Releases: 11.2(2i) 11.2(2j) 11.2(3f) 11.2(3g) 11.2(3h) 11.2(3l) 11.3(0.236) 11.3(1j) 11.3(2i) 11.3(2j) 12.0(1r).
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Application Policy Infrastructure Controller | 1.2\(2\) |
| Cisco | Application Policy Infrastructure Controller | 1.2\(3\) |
| Cisco | Application Policy Infrastructure Controller | 1.3\(1\) |
| Cisco | Application Policy Infrastructure Controller | 1.3\(2\) |
| Cisco | Application Policy Infrastructure Controller | 2.0\(1\) |
| Cisco | Nx-Os | 11.2\(2g\) |
| Cisco | Nx-Os | 11.2\(2h\) |
| Cisco | Nx-Os | 11.2\(2i\) |
| Cisco | Nx-Os | 11.2\(3c\) |
| Cisco | Nx-Os | 11.2\(3e\) |
| Cisco | Nx-Os | 11.2\(3h\) |
| Cisco | Nx-Os | 11.3\(1i\) |
| Cisco | Nx-Os | 11.3\(2f\) |
| Cisco | Nx-Os | 11.3\(2h\) |
| Cisco | Nx-Os | 11.3\(2i\) |
| Cisco | Nx-Os | 12.0\(1m\) |
| Cisco | Nx-Os | 12.0\(1n\) |
| Cisco | Nx-Os | 12.0\(1o\) |
| Cisco | Nx-Os | 12.0\(1p\) |
| Cisco | Nx-Os | 12.0\(1q\) |
References
- http://www.securityfocus.com/bid/94077Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037185Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-n9kapicMitigation, Vendor Advisory
- http://www.securityfocus.com/bid/94077Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1037185Third Party Advisory, VDB Entry
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-n9kapicMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6457?
How severe is CVE-2016-6457?
How do I fix CVE-2016-6457?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-6450A vulnerability in the package unbundle utility of Cisco IOS…
- CVE-2016-6451Multiple vulnerabilities in the web framework code of the Ci…
- CVE-2016-6452A vulnerability in the web-based graphical user interface (G…
- CVE-2016-6453A vulnerability in the web framework code of Cisco Identity …
- CVE-2016-6454A cross-site request forgery (CSRF) vulnerability in the web…
- CVE-2016-6455A vulnerability in the Slowpath of StarOS for Cisco ASR 5500…
- CVE-2016-6458A vulnerability in the content filtering functionality of Ci…
- CVE-2016-6459Cisco TelePresence endpoints running either CE or TC softwar…
- CVE-2016-6460A vulnerability in the FTP Representational State Transfer A…
- CVE-2016-6461A vulnerability in the HTTP web-based management interface o…
- CVE-2016-6462A vulnerability in the email filtering functionality of Cisc…
- CVE-2016-6463A vulnerability in the email filtering functionality of Cisc…
Are you affected by CVE-2016-6457?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
