7.8
CVSSv2

CVE-2016-6386

Published: 05/10/2016 Updated: 29/09/2020
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

Cisco IOS XE 3.1 up to and including 3.17 and 16.1 on 64-bit platforms allows remote malicious users to cause a denial of service (data-structure corruption and device reload) via fragmented IPv4 packets, aka Bug ID CSCux66005.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ios xe 3.9.0s

cisco ios xe 3.12.4s

cisco ios xe 3.6.2s

cisco ios xe 3.4.2s

cisco ios xe 3.7.4s

cisco ios xe 3.7.2e

cisco ios xe 3.12.1s

cisco ios xe 3.16.1as

cisco ios xe 3.3.5se

cisco ios xe 3.10.5s

cisco ios xe 3.2.1se

cisco ios xe 3.9.0as

cisco ios xe 3.3sg 3.3.2sg

cisco ios xe 3.3xo 3.3.2xo

cisco ios xe 3.1.4as

cisco ios xe 3.4.1s

cisco ios xe 3.3.3se

cisco ios xe 3.6.2e

cisco ios xe 3.13.4s

cisco ios xe 3.7.5s

cisco ios xe 3.1.0s

cisco ios xe 3.3sg 3.3.1sg

cisco ios xe 3.4sg 3.4.2sg

cisco ios xe 3.1.2s

cisco ios xe 3.5.0s

cisco ios xe 3.3xo 3.3.0xo

cisco ios xe 3.5.3e

cisco ios xe 3.9.1as

cisco ios xe 3.4.6s

cisco ios xe 3.10.4s

cisco ios xe 3.14.0s

cisco ios xe 3.3.1sq

cisco ios xe 3.16.0s

cisco ios xe 3.3.4se

cisco ios xe 3.15.2s

cisco ios xe 3.7.3s

cisco ios xe 3.4sg 3.4.0sg

cisco ios xe 3.7.2ts

cisco ios xe 3.5.0e

cisco ios xe 3.4.5s

cisco ios xe 3.8.1s

cisco ios xe 3.15.1s

cisco ios xe 3.7.1e

cisco ios xe 3.11.1s

cisco ios xe 3.7.0s

cisco ios xe 3.3.2se

cisco ios xe 3.13.0s

cisco ios xe 3.16.0cs

cisco ios xe 3.2.1s

cisco ios xe 3.8.0s

cisco ios xe 3.5.3sq

cisco ios xe 3.4.0as

cisco ios xe 3.17.0s

cisco ios xe 3.10.2s

cisco ios xe 3.6.1s

cisco ios xe 3.2.3se

cisco ios xe 3.10.3s

cisco ios xe 3.15.1cs

cisco ios xe 3.11.0s

cisco ios xe 3.3sg 3.3.0sg

cisco ios xe 3.2.2se

cisco ios xe 3.5.2s

cisco ios xe 3.5.1e

cisco ios xe 3.3xo 3.3.1xo

cisco ios xe 3.6.4e

cisco ios xe 3.13.2s

cisco ios xe 3.10.1s

cisco ios xe 3.8.0e

cisco ios xe 3.6.1e

cisco ios xe 3.12.0s

cisco ios xe 3.4.3s

cisco ios xe 3.6.0e

cisco ios xe 3.1.1s

cisco ios xe 3.4.0s

cisco ios xe 3.14.1s

cisco ios xe 3.3.0s

cisco ios xe 3.3.0sq

cisco ios xe 3.14.3s

cisco ios xe 3.10.7s

cisco ios xe 3.5.1sq

cisco ios xe 3.12.2s

cisco ios xe 3.7.2s

cisco ios xe 3.10.6s

cisco ios xe 3.14.2s

cisco ios xe 3.3.0se

cisco ios xe 3.4sg 3.4.1sg

cisco ios xe 3.6.0s

cisco ios xe 3.9.2s

cisco ios xe 3.13.0as

cisco ios xe 3.9.1s

cisco ios xe 3.7.3e

cisco ios xe 3.2.2s

cisco ios xe 3.1.4s

cisco ios xe 3.6.2ae

cisco ios xe 3.7.6s

cisco ios xe 3.1.0sg

cisco ios xe 3.8.2s

cisco ios xe 3.8.1e

cisco ios xe 3.10.1xbs

cisco ios xe 3.3.1s

cisco ios xe 3.7.4as

cisco ios xe 3.4.1sq

cisco ios xe 3.8.0ex

cisco ios xe 3.4sg 3.4.6sg

cisco ios xe 3.4sg 3.4.3sg

cisco ios xe 3.3.1se

cisco ios xe 3.5.2sq

cisco ios xe 3.2ja 3.2.0ja

cisco ios xe 3.10.0s

cisco ios xe 3.11.3s

cisco ios xe 16.1 16.1.2

cisco ios xe 3.3.2s

cisco ios xe 3.5.1s

cisco ios xe 3.5.2e

cisco ios xe 3.1.1sg

cisco ios xe 3.6.3e

cisco ios xe 3.15.0s

cisco ios xe 3.11.4s

cisco ios xe 3.5.0sq

cisco ios xe 3.4.4s

cisco ios xe 3.4sg 3.4.4sg

cisco ios xe 3.4sg 3.4.7sg

cisco ios xe 3.4.0sq

cisco ios xe 3.12.0as

cisco ios xe 3.2.0se

cisco ios xe 3.13.1s

cisco ios xe 3.12.3s

cisco ios xe 3.4sg 3.4.5sg

cisco ios xe 3.13.3s

cisco ios xe 3.7.1s

cisco ios xe 3.1.3as

cisco ios xe 3.16.1s

cisco ios xe 3.13.2as

cisco ios xe 3.11.2s

Vendor Advisories

A vulnerability in the IPv4 fragment reassembly function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload The vulnerability is due to the corruption of an internal data structure that occurs when the affected software reassembles an IPv4 packet An attacker could exploit this vulnerabi ...