Resource exhaustion - CVE-2016-4921

 

Resource exhaustion - CVE-2016-4921

Published: October 14, 2016 / Updated: October 14, 2016


Vulnerability identifier: #VU1000
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: CVE-2016-4921
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor:
Affected software:

Detailed vulnerability description

The vulnerability allows a remote unauthenticated user to consume excessive resources on the target system.
The weakness is cuased by insufficient input control. By sending a specially crafted IPv6, attackers can prevent the system from storing next hop information or cause a kernel panic.
Successful exploitation of the vulnerability may result in denial of service on the vulnerable system.

How to mitigate CVE-2016-4921

Update to one of the fixed versions: 12.3X48-D30, 13.3R10, 14.1R8, 14.1X53-D40, 14.2R6, 15.1F2-S5, 15.1F5-S2, 15.1F6, 15.1R3, 15.1X49-D40, 15.1X53-D70 or 16.1R1.

Sources