CVE-2016-1327
9.8
CRITICAL · CVSS 3.0 · EPSS 6.9% (pctl 94)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCuv05935.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 6.85% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-03-09 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| cisco | dpc2203 |
| cisco | dpc2203 cable modem firmware |
| cisco | epc2203 |
| cisco | epc2203 cable modem firmware |
References
- http://www.securityfocus.com/bid/84279
- http://www.securitytracker.com/id/1035235
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160309-cmre
- http://www.securityfocus.com/bid/84279
- http://www.securitytracker.com/id/1035235
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160309-cmre
→ the Explorer · watch your stack · NVD