CVE-2016-1313 describes a critical vulnerability in Cisco UCS Invicta C3124SA Appliance versions 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner, where a default SSH private key is improperly stored. This flaw allows remote attackers to gain root access with high confidentiality, integrity, and availability impact, as reflected by its CVSS v3 score of 9.8 (CRITICAL) due to its network-based attack vector and low complexity. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in the KEV catalog, the vulnerability has received some community discussion and media coverage, indicating awareness despite no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.3.1CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_invicta_c3124sa_appliance:4.3.1:*:*:*:*:*:*:* | ||
4.5.0CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_invicta_c3124sa_appliance:4.5.0:*:*:*:*:*:*:* | ||
5.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:ucs_invicta_c3124sa_appliance:5.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.