Vulnerability Description
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios | 12.0\(1\) |
| Cisco | Ios Xe | 2.1.0 |
| Cisco | Ios Xr | 2.0.0 |
| Cisco | Nx-Os | 1.0\(1.110a\) |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-ipv6-enThird Party Advisory
- http://www.securityfocus.com/bid/90872Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035962Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035963Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035964Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035965Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1036651
- http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20Vendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-ipv6-enThird Party Advisory
- http://www.securityfocus.com/bid/90872Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035962Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035963Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035964Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1035965Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-1409?
CVE-2016-1409 is a vulnerability with a CVSS score of 7.5 (HIGH). The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (pac...
How severe is CVE-2016-1409?
CVE-2016-1409 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-1409?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ios, Cisco Ios Xe, Cisco Ios Xr, Cisco Nx-Os.