SB2016100607 - Information disclosure in Cisco Catalyst 6800 Series Switches



SB2016100607 - Information disclosure in Cisco Catalyst 6800 Series Switches

Published: October 6, 2016 Updated: April 5, 2018

Security Bulletin ID SB2016100607
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2016-6422)

The vulnerability allows a remote unauthenticated user to access potentially sensitive information on the target system.
The weakness occurs when the ternary content addressable memory (TCAM) implements insufficient access control entries (ACEs) in the port access control list. By sending a specially crafted packets attackers can bypass ACEs that lets them obtain important data.
Successful exploitation of the vulnerabilitymau result in information disclosure.

Remediation

Install update from vendor's website.