CVE-2016-1367
published 2016-04-21CVE-2016-1367: The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload)…
PriorityP339high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.95%
77.9th percentile
The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID CSCus23248.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | adaptive_security_appliance | — | — |
| cisco | adaptive_security_appliance_software | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-548p-w9c9-gw4q: The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9
ghsa_unreviewed·2022-05-17
CVE-2016-1367 [HIGH] GHSA-548p-w9c9-gw4q: The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9
The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (device reload) via crafted DHCPv6 packets, aka Bug ID CSCus23248.
Cisco
Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability
vendor_cisco·2016-04-20·CVSS 7.8
CVE-2016-1367 [HIGH] CWE-399 Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability
Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability
A vulnerability in the DHCPv6 relay feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
The vulnerability is due to insufficient validation of DHCPv6 packets. An attacker could exploit this vulnerability by sending crafted DHCPv6 packets to an affected device, resulting in a denial of service (DoS) condition.
This vulnerability affects systems configured in routed firewall mode and in single or multiple context mode. Cisco ASA Software is affected by this vulnerability only if the software is configured with the DHCPv6 relay feature. The vulnerability is triggered only by IPv6 traffic.
This vulnerability a
Cisco
Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability
vendor_cisco
CVE-2016-1367 Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability
CVE-2016-1367: Cisco Adaptive Security Appliance Software DHCPv6 Relay Denial of Service Vulnerability
A vulnerability in the DHCPv6 relay feature of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an affected device to reload. The vulnerability is due to insufficient validation of DHCPv6 packets. An attacker could exploit this vulnerability by sending crafted DHCPv6 packets to an affected device, resulting in a denial of service (DoS) condition. This vulnerability affects systems configured in routed firewall mode and in single or multiple context mode. Cisco ASA Software is affected by this vulnerability only if the software is configured with the DHCPv6 relay feature. The vulnerability is triggered only by IPv6 traffic. This vuln
No detection rules found.
No public exploits indexed.
2016-04-21
Published