#VU11757 Resource management errors in Cisco IOS XE - CVE-2016-1349

 

#VU11757 Resource management errors in Cisco IOS XE - CVE-2016-1349

Published: April 11, 2018


Vulnerability identifier: #VU11757
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2016-1349
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Cisco IOS XE
Software vendor:
Cisco Systems, Inc

Description

The vulnerability allows a remote unauthenticated attacker to cause DoS condition on the target system.

The weakness exists due to incorrect handling of image list parameters. A remote attacker can send specially crafted Smart Install packets to TCP port 4786 and cause the service to crash.

Remediation

Update to versions 15.2(5.5.64)E, 15.2(5.5.63)E, 15.2(5.1.3)E, 15.2(5)E, 15.2(4.1.13)E, 15.2(4.1.5a)E, 15.2(4.0.95a)E, 15.2(4)E3, 15.2(4)E2, 15.2(4)E1, 15.2(4)E, 15.2(3)E3, 15.2(2.0.2)EA3, 15.2(2)EA3, 15.2(2)E4, 15.1(2)SG7, 15.0(2.1.94)SG11, 15.0(2.1.91)SG11, 15.0(2)SG11, 15.0(2)SE9, 15.0(2)EX11, 15.0(2)EX10, 12.2(60)EZ9, 12.2(55)SE11, 3.9(0)E, 3.8(0)E, 3.7(3)E or 3.6(4)E.

External links