7.8
CVSSv2

CVE-2016-1349

Published: 26/03/2016 Updated: 03/12/2016
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 up to and including 3.7 allows remote malicious users to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.4sg 3.4.2sg

cisco ios xe 3.4sg 3.4.6sg

cisco ios xe 3.5e 3.5.2e

cisco ios xe 3.5e 3.5.1e

cisco ios xe 3.6e 3.6.2e

cisco ios xe 3.6e 3.6.1e

samsung x14j firmware t-ms14jakucb-1102.5

cisco ios xe 3.3se 3.3.1se

cisco ios xe 3.6e 3.6.0e

cisco ios xe 3.2se 3.2.3se

cisco ios xe 3.4sg 3.4.5sg

cisco ios xe 3.4sg 3.4.1sg

cisco ios xe 3.3se 3.3.0se

cisco ios xe 3.5e 3.5.3e

cisco ios xe 3.3xo 3.3.0xo

cisco ios xe 3.2se 3.2.1se

sun opensolaris snv 124

cisco ios xe 3.3se 3.3.3se

cisco ios xe 3.7e 3.7.0e

cisco ios xe 3.7e 3.7.1e

cisco ios xe 3.7e 3.7.2e

cisco ios xe 3.2se 3.2.0se

cisco ios xe 3.2ja 3.2.0ja

cisco ios xe 3.3xo 3.3.2xo

cisco ios xe 3.3se 3.3.2se

cisco ios xe 3.3se 3.3.4se

cisco ios xe 3.6e 3.6.2ae

cisco ios xe 3.4sg 3.4.3sg

cisco ios xe 3.3xo 3.3.1xo

cisco ios xe 3.2se 3.2.2se

cisco ios xe 3.5e 3.5.0e

cisco ios xe 3.4sg 3.4.0sg

cisco ios xe 3.3se 3.3.5se

cisco ios xe 3.4sg 3.4.4sg

intel core i5-9400f firmware -

zyxel gs1900-10hp firmware

netgear jr6150 firmware

zzinc keymouse firmware 3.08

Vendor Advisories

The Smart Install client feature in Cisco IOS and IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device The vulnerability is due to incorrect handling of image list parameters An attacker could exploit this vulnerability by sending crafted ...
In recent weeks, Cisco has published several documents related to the Smart Install feature: one Talos blog about potential misuse of the feature if left enabled, and two Cisco Security Advisories that were included in the March 2018 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication Given the heightened awareness, ...