CVE-2016-1333
published 2016-02-17CVE-2016-1333: Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an…
PriorityP430medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.64%
74.0th percentile
Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | 1000_series_connected_grid_routers | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| salesforce | tough-cookie | >= 0 < 2.3.0 | 2.3.0 |
| tibco | hawk | >= 0 < 3.1.3 | 3.1.3 |
| tibco | hawk | >= 4.0.0 < 4.1.1 | 4.1.1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hgh-fw5m-38cf: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-1333 [MEDIUM] GHSA-2hgh-fw5m-38cf: Cisco IOS 15
Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.
GHSA
ReDoS via long string of semicolons in tough-cookie
ghsa·2018-10-10
CVE-2016-1000232 [MEDIUM] CWE-1333 ReDoS via long string of semicolons in tough-cookie
ReDoS via long string of semicolons in tough-cookie
Affected versions of `tough-cookie` may be vulnerable to regular expression denial of service when long strings of semicolons exist in the `Set-Cookie` header.
## Recommendation
Update to version 2.3.0 or later.
GHSA
Regular Expression Denial of Service in hawk
ghsa·2018-07-31
CVE-2016-2515 [HIGH] CWE-1333 Regular Expression Denial of Service in hawk
Regular Expression Denial of Service in hawk
Versions of `hawk` prior to 3.1.3, or 4.x prior to 4.1.1 are affected by a regular expression denial of service vulnerability related to excessively long headers and URI's.
## Recommendation
Update to hawk version 4.1.1 or later.
GHSA
Regular Expression Denial of Service in is-my-json-valid
ghsa·2017-10-24
CVE-2016-2537 [HIGH] CWE-1333 Regular Expression Denial of Service in is-my-json-valid
Regular Expression Denial of Service in is-my-json-valid
Version of `is-my-json-valid` before 2.12.4 are vulnerable to regular expression denial of service (ReDoS) via the email validation function.
## Recommendation
Update to version 2.12.4 or later.
Cisco
Cisco 1000 Series Connected Grid Routers SNMP BRIDGE MIB Denial of Service Vulnerability
vendor_cisco·2016-02-17·CVSS 6.8
CVE-2016-1333 [MEDIUM] CWE-399 Cisco 1000 Series Connected Grid Routers SNMP BRIDGE MIB Denial of Service Vulnerability
Cisco 1000 Series Connected Grid Routers SNMP BRIDGE MIB Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) BRIDGE Management Information Base (MIB) of the Cisco 1000 Series Connected Grid Routers could allow an authenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to a faulty implementation of certain SNMP Object Identifiers (OIDs) within the BRIDGE MIB. An SNMP request for certain Object Identifiers (OIDs) within the BRIDGE MIB can cause the device to reload unexpectedly. If an attacker knows the SNMP community string, the attacker could exploit this vulnerability by performing an authenticated SNMP request of the BRIDGE MIB OID to an affected device. An exploit could allow the attacker to cau
Cisco
Cisco 1000 Series Connected Grid Routers SNMP BRIDGE MIB Denial of Service Vulnerability
vendor_cisco
CVE-2016-1333 Cisco 1000 Series Connected Grid Routers SNMP BRIDGE MIB Denial of Service Vulnerability
CVE-2016-1333: Cisco 1000 Series Connected Grid Routers SNMP BRIDGE MIB Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) BRIDGE Management Information Base (MIB) of the Cisco 1000 Series Connected Grid Routers could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a faulty implementation of certain SNMP Object Identifiers (OIDs) within the BRIDGE MIB. An SNMP request for certain Object Identifiers (OIDs) within the BRIDGE MIB can cause the device to reload unexpectedly. If an attacker knows the SNMP community string, the attacker could exploit this vulnerability by performing an authenticated SNMP request of the BRIDGE MIB OID to an affected device. An exploit could allow the at
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-02-17
Published