CVE-2016-1409

Description

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
4.876

Associated Vulnerability

VulnerabilityOS Platform
Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability For Cisco Adaptive Security Appliance (ASA) SoftwareNCM
Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability For Cisco IOSNCM
Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability For Cisco IOS XE SoftwareNCM
Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability For Cisco NX-OS SoftwareNCM
Improper Input Validation Vulnerability (CVE-2016-1409)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1706057Security Update for Cisco Adaptive Security Appliance (ASA) Software 99.17(1.69)
PATCH-1706090Security Update for Cisco IOS Amsterdam-17.2.1r
PATCH-1706107Security Update for Cisco IOS XE Software 5.2(1)SV5(1.3a)
PATCH-1706149Security Update for Cisco NX-OS Software 4.1(3a)UCSM

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234