CVE-2016-8209
Summary
| CVE | CVE-2016-8209 |
|---|---|
| State | PUBLISHED |
| Assigner | brocade |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-08 18:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module. |
Risk And Classification
Primary CVSS: v3.0 7.5 HIGH from [email protected]
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-754 | Denial of Service Attack
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 5 | AV:N/AC:L/Au:N/C:N/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Brocade | Netiron Cer 2024c-4x-rt | - | All | All | All |
| Hardware | Brocade | Netiron Cer 2024f-4x-rt | - | All | All | All |
| Hardware | Brocade | Netiron Cer 2024f-rt | - | All | All | All |
| Hardware | Brocade | Netiron Cer 2048fx-rt | - | All | All | All |
| Operating System | Brocade | Netiron Cer Series Firmware | - | All | All | All |
| Hardware | Brocade | Netiron Ces 2024c-4x | - | All | All | All |
| Hardware | Brocade | Netiron Ces 2024f-4x | - | All | All | All |
| Hardware | Brocade | Netiron Ces 2048fx | - | All | All | All |
| Operating System | Brocade | Netiron Ces Series Firmware | - | All | All | All |
| Hardware | Brocade | Netiron Mlxe-16 | - | All | All | All |
| Hardware | Brocade | Netiron Mlxe-32 | - | All | All | All |
| Hardware | Brocade | Netiron Mlxe-4 | - | All | All | All |
| Hardware | Brocade | Netiron Mlxe-8 | - | All | All | All |
| Operating System | Brocade | Netiron Mlx Series Firmware | - | All | All | All |
| Hardware | Brocade | Netiron Xmr 16000 | - | All | All | All |
| Hardware | Brocade | Netiron Xmr 32000 | - | All | All | All |
| Hardware | Brocade | Netiron Xmr 4000 | - | All | All | All |
| Hardware | Brocade | Netiron Xmr 8000 | - | All | All | All |
| Operating System | Brocade | Netiron Xmr Series Firmware | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Brocade Communications Systems Inc. | NetIron XMR/MLX And Brocade CES/CER On NetIron | affected NetIron 05.8.00 and later releases up to and including 06.1.00 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Brocade NetIron SSH Port Flaw Lets Remote Users Cause the Target System to Reload - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE-2016-8209 | af854a3a-2127-422b-91ae-364da2661108 | www.brocade.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.