CVE-2016-6398
Published on: 09/12/2016 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:12 PM UTC
Certain versions of Ios from Cisco contain the following vulnerability:
The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from earlier network communication by reading packet data, aka Bug ID CSCvb16274.
- CVE-2016-6398 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
|
---|---|---|---|---|
NETWORK | LOW | NONE | NONE | |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
|
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Cisco IOS PPTP Server Bug Lets Remote Users Obtain Potentially Sensitive Information from Packet Buffer Memory on the Target System - SecurityTracker | www.securitytracker.com text/html |
![]() |
Cisco IOS CVE-2016-6398 Information Disclosure Vulnerability | cve.report (archive) text/html |
![]() |
Cisco IOS Software Point-to-Point Tunneling Protocol Server Information Disclosure Vulnerability | Vendor Advisory tools.cisco.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Cisco | Ios | 15.5\(3\)m | All | All | All |
Operating System | Cisco | Ios | 15.5\(3\)m | All | All | All |
- cpe:2.3:o:cisco:ios:15.5\(3\)m:*:*:*:*:*:*:*:
- cpe:2.3:o:cisco:ios:15.5\(3\)m:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE