CVE-2016-6412

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.
Configurations

Configuration 1 (hide)

cpe:2.3:o:cisco:ios:15.6\(1\)t1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:56

Type Values Removed Values Added
References () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-caf1 - Vendor Advisory () http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-caf1 - Vendor Advisory
References () http://www.securityfocus.com/bid/93088 - () http://www.securityfocus.com/bid/93088 -
References () http://www.securitytracker.com/id/1036874 - () http://www.securitytracker.com/id/1036874 -

Information

Published : 2016-09-24 01:59

Updated : 2024-11-21 02:56


NVD link : CVE-2016-6412

Mitre link : CVE-2016-6412

CVE.ORG link : CVE-2016-6412


JSON object : View

Products Affected

cisco

  • ios
CWE
CWE-20

Improper Input Validation