CVE-2016-1340 is a high-severity heap-based buffer overflow vulnerability affecting specific versions of Cisco Unified Computing System (UCS) Platform Emulator. A local attacker can exploit this flaw by providing crafted filename arguments to the libclimeta.so library, potentially leading to privilege escalation. With a CVSS score of 8.4, this vulnerability poses a significant risk due to its high impact on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and it is not listed in CISA's KEV catalog, its presence in the FAUCET Hot List and a single community mention indicate some level of awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5\(2\)ts4CPE matchmatch criteria | cpe:2.3:a:cisco:unified_computing_system_platform_emulator:2.5\(2\)ts4:*:*:*:*:*:*:* | ||
3.0\(2c\)aCPE matchmatch criteria | cpe:2.3:a:cisco:unified_computing_system_platform_emulator:3.0\(2c\)a:*:*:*:*:*:*:* | ||
3.0\(2c\)ts9CPE matchmatch criteria | cpe:2.3:a:cisco:unified_computing_system_platform_emulator:3.0\(2c\)ts9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Cisco Unified Computing System - Multiple Vulnerabilities
Apr 15, 2016[R1] Cisco Unified Computing System - Multiple Vulnerabilities
Apr 15, 2016[R1] Cisco Unified Computing System - Multiple Vulnerabilities
Apr 15, 2016