Heap-based Buffer Overflow in Cisco Unified Computing System Platform Emulator
CVE-2016-1340
8.4HIGH
Key Information:
- Vendor
- Cisco
- Vendor
- CVE Published:
- 16 April 2016
Summary
This vulnerability in the Cisco Unified Computing System (UCS) Platform Emulator allows local users to exploit a heap-based buffer overflow via crafted arguments in the libclimeta.so filename. Successful exploitation can grant escalated privileges to the attackers, posing a serious security risk across the affected UCS versions.
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved