Resource management errors in Cisco IOS XE - CVE-2016-1349
Published: April 11, 2018
Vulnerability identifier: #VU11757
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-1349
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.
The weakness exists due to incorrect handling of image list parameters. A remote attacker can send specially crafted Smart Install packets to TCP port 4786 and cause the service to crash.
The weakness exists due to incorrect handling of image list parameters. A remote attacker can send specially crafted Smart Install packets to TCP port 4786 and cause the service to crash.
Affected software
Cisco IOS XE
How to mitigate CVE-2016-1349
Update to versions 15.2(5.5.64)E, 15.2(5.5.63)E, 15.2(5.1.3)E, 15.2(5)E, 15.2(4.1.13)E, 15.2(4.1.5a)E, 15.2(4.0.95a)E, 15.2(4)E3, 15.2(4)E2, 15.2(4)E1, 15.2(4)E, 15.2(3)E3, 15.2(2.0.2)EA3, 15.2(2)EA3, 15.2(2)E4, 15.1(2)SG7, 15.0(2.1.94)SG11, 15.0(2.1.91)SG11, 15.0(2)SG11, 15.0(2)SE9, 15.0(2)EX11, 15.0(2)EX10, 12.2(60)EZ9, 12.2(55)SE11, 3.9(0)E, 3.8(0)E, 3.7(3)E or 3.6(4)E.