Buffer overflow in Cisco Cable Modem with Digital Voice Model DPC2203 and Cisco Cable Modem with Digital Voice Model EPC2203 - CVE-2016-1327

 

Buffer overflow in Cisco Cable Modem with Digital Voice Model DPC2203 and Cisco Cable Modem with Digital Voice Model EPC2203 - CVE-2016-1327

Published: March 9, 2016 / Updated: January 11, 2017


Vulnerability identifier: #VU4203
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1327
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image. A remote attacker can execute arbitrary code on the target system via a specially crafted HTTP request, aka Bug ID CSCuv05935.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Cisco Cable Modem with Digital Voice Model DPC2203
Cisco Cable Modem with Digital Voice Model EPC2203

How to mitigate CVE-2016-1327

Contact customer support to obtain fixed version of firmware.


External References

Related Security Bulletins