Back to search
CVE-2016-6412
Published: Sep 24, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
93088
vdb-entry
x_refsource_BID
20160921 Cisco Application-Hosting Framework HTTP Header Injection Vulnerability
vendor-advisory
x_refsource_CISCO
1036874
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now