CVE-2016-1321: Cisco Universal Small Cell Firmware

Medium severity, CVSS 5.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to bypass a certain certificate-validation feature and obtain sensitive firmware-image and IP address data via a request to an unspecified Cisco server, aka Bug ID CSCut98082.

Affected products

  • Cisco Universal Small Cell Firmware: version r2.12_base only; version r2.13_base only; version r2.14_base only; version r2.15_base only; version r2.16_base only; version r2.17_base only; …

Published 2016-02-15. Last modified 2026-06-17.