CVE-2016-6374 describes a critical vulnerability in Cisco Cloud Services Platform (CSP) 2100 version 2.0, allowing remote attackers to execute arbitrary code. This high-severity flaw, with a CVSS score of 9.8, enables unauthenticated attackers to achieve full compromise (confidentiality, integrity, availability) by sending a crafted dnslookup command within an HTTP request. While no public exploit code or Metasploit modules are available, and it's not listed in CISA's KEV catalog, the vulnerability has received limited community discussion and media coverage, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:cloud_services_platform_2100:2.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.