Tech Analysis research archive
Tech Analysis discovers arbitrary code execution vulnerability in Cisco EPC2203 and DPC2203 cable modems, CVE-2016-1327
Tech Analysis is no longer trading. This website is maintained as the personal profile and research archive of its founder, Chris Watts, who now works at CyberCX. Earlier research remains attributed to Tech Analysis as originally published.
What was reported
On 9 March 2016 Cisco published an advisory for a buffer overflow in the web server of its Cable Modem with Digital Voice models DPC2203 and EPC2203, assigned CVE-2016-1327. In Cisco's words, improper input validation for HTTP requests could allow an unauthenticated, remote attacker to send a crafted HTTP request and cause arbitrary code execution. Cisco gave it the maximum CVSS v2 base score of 10.0. SecurityWeek and Security Affairs reported the advisory in March 2016, naming Chris Watts.
Tech Analysis announced the finding on this page on 1 September 2016, noting that these modems were widely deployed by cable internet providers in Australia and elsewhere.
Primary sources
- Cisco: Cisco Cable Modem with Digital Voice Remote Code Execution Vulnerability (first published 9 March 2016)
- CVE-2016-1327 on cve.org
- Archived copy of the original Tech Analysis article (Internet Archive)
- SecurityWeek, 11 March 2016: Serious Flaws Patched in Cisco Modems, Gateways
Attribution
Cisco's advisory states: "Cisco would like to thank Chris Watts of Tech Analysis for reporting this vulnerability."
See the full research index for all public vulnerability records credited to Chris Watts.