CVE-2016-1370

Description

Cisco Prime Network Analysis Module (NAM) before 6.2(1-b) miscalculates IPv6 payload lengths, which allows remote attackers to cause a denial of service (mond process crash and monitoring outage) via crafted IPv6 packets, aka Bug ID CSCuy37324.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
Exploitation Probability
0.465

Associated Vulnerability

VulnerabilityOS Platform
Cisco Prime Network Analysis Module IPv6 Denial of Service Vulnerability For Cisco Prime Network Analysis Module SoftwareNCM
Improper Input Validation Vulnerability (CVE-2016-1370)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706008Security Update for Cisco Prime Network Analysis Module Software 6.2(3)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234