7.5
CVSSv3

CVE-2016-6355

Published: 23/08/2016 Updated: 28/11/2016
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Memory leak in Cisco IOS XR 5.1.x up to and including 5.1.3, 5.2.x up to and including 5.2.5, and 5.3.x up to and including 5.3.2 on ASR 9001 devices allows remote malicious users to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xr 5.1.3

cisco ios xr 5.2.0

cisco ios xr 5.3.2

cisco ios xr 5.2.3

cisco ios xr 5.2.1

cisco ios xr 5.2.2

cisco ios xr 5.2.5

cisco ios xr 5.1.1

cisco ios xr 5.1.2

cisco ios xr 5.3.1

cisco ios xr 5.2.4

cisco ios xr 5.1.0

cisco ios xr 5.3.0

cisco ios xr 5.1.1.k9sec

Vendor Advisories

A vulnerability in the driver processing functions of Cisco IOS XR Software for Cisco ASR 9001 Aggregation Services Routers could allow an unauthenticated, remote attacker to cause a memory leak on the route processor (RP) of an affected device, which could cause the device to drop all control-plane protocols and lead to a denial of service conditi ...