CVE-2016-1452

MEDIUM

Cisco ASR 5000 <20.0.0 - Privilege Escalation

Title source: llm

Description

Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of the read-write community, aka Bug ID CSCuz29526.

Scores

CVSS v3 6.5
EPSS 0.0027
EPSS Percentile 49.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-254 CWE-200
Status draft

Affected Products (12)

cisco/asr_5000
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software
cisco/asr_5000_software

Timeline

Published Jul 15, 2016
Tracked Since Feb 18, 2026