HIGH · 7.5

CVE-2016-1350

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug...

Vulnerability Description

Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
CiscoIos Xe3.8.0s
LenovoThinkcentre E75S Firmware< m16kt61a
SamsungX14J Firmwaret-ms14jakucb-1102.5
SunOpensolarissnv_124
ZyxelGs1900-10Hp Firmware< 2.50\(aazi.0\)c0
ZzincKeymouse Firmware3.08

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-1350?

CVE-2016-1350 is a vulnerability with a CVSS score of 7.5 (HIGH). Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug...

How severe is CVE-2016-1350?

CVE-2016-1350 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-1350?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios Xe, Lenovo Thinkcentre E75S Firmware, Samsung X14J Firmware, Sun Opensolaris, Zyxel Gs1900-10Hp Firmware.