Vulnerability Bulletins |
Cisco Universal Small Cell Devices Unauthorized Firmware Retrieval Vulnerability |
|
| Affected software | Cisco |
|
A vulnerability in Cisco Universal Small Cell devices could allow an unauthenticated, remote attacker to retrieve firmware from a Cisco-hosted binary server. The vulnerability is due to insufficient enforcement of the two-way certificate validation process by the Cisco-hosted binary server to ensure that only Cisco Universal Small Cell devices are able to download the firmware images and service provider configuration hints file.The hints file contains IP addresses of the devices provisioned More info: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160212-usc?vs_f=Cisco%20Security%20Advisory&vs_cat=Security%20Intelligence&vs_type=RSS&vs_p=Cisco%20Universal%20Small%20Cell%20Devices%20Unauthorized%20Firmware%20Retriev |
|






