CVE-2016-9223 describes a critical vulnerability in Cisco CloudCenter Orchestrator (CCO) where an unauthenticated, remote attacker can install Docker containers with high privileges. This flaw affects all CCO deployments where Docker Engine TCP port 2375 is openly accessible and bound to any interface. With a CVSS score of 9.8 (CRITICAL), the vulnerability allows for complete compromise of confidentiality, integrity, and availability due to its network-based attack vector and low complexity. While no public exploit code is readily available, SecurityWeek reported active exploitation, indicating real-world risk despite limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.4.0CPE matchmatch criteria | cpe:2.3:a:cisco:cloudcenter_orchestrator:4.4.0:*:*:*:*:*:*:* | ||
4.5.0CPE matchmatch criteria | cpe:2.3:a:cisco:cloudcenter_orchestrator:4.5.0:*:*:*:*:*:*:* | ||
4.6.0CPE matchmatch criteria | cpe:2.3:a:cisco:cloudcenter_orchestrator:4.6.0:*:*:*:*:*:*:* | ||
4.6.1CPE matchmatch criteria | cpe:2.3:a:cisco:cloudcenter_orchestrator:4.6.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.