CVE-2016-9223
CRITICALCisco CloudCenter Orchestrator - Privilege Escalation
Title source: llmDescription
A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow an unauthenticated, remote attacker to install Docker containers with high privileges on the affected system. Affected Products: This vulnerability affect all releases of Cisco CloudCenter Orchestrator (CCO) deployments where the Docker Engine TCP port 2375 is open on the system and bound to local address 0.0.0.0 (any interface).
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/95024
Mitigation, Vendor Advisory x_refsource_confirm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161221-cco
Scores
CVSS v3
9.8
EPSS
0.0293
EPSS Percentile
85.6%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-264
Status
published
Products (5)
cisco/cloudcenter_orchestrator
4.4.0
cisco/cloudcenter_orchestrator
4.5.0
cisco/cloudcenter_orchestrator
4.6.0
cisco/cloudcenter_orchestrator
4.6.1
n/a/Cisco CloudCenter Orchestrator
Cisco CloudCenter Orchestrator
Published
Dec 26, 2016
Tracked Since
Feb 18, 2026