CVE-2016-1407
published 2016-05-25CVE-2016-1407: Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service…
PriorityP335high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.76%
75.7th percentile
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.
Affected
80 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fwrp-vrm8-wjwg: Cisco IOS XR through 5
ghsa_unreviewed·2022-05-17
CVE-2016-1407 [HIGH] CWE-20 GHSA-fwrp-vrm8-wjwg: Cisco IOS XR through 5
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.
Cisco
Cisco IOS XR Software LPTS Denial of Service Vulnerability
vendor_cisco·2016-05-20·CVSS 5.0
CVE-2016-1407 [MEDIUM] CWE-399 Cisco IOS XR Software LPTS Denial of Service Vulnerability
Cisco IOS XR Software LPTS Denial of Service Vulnerability
A vulnerability in the Local Packet Transport Services (LPTS) network stack of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a limited denial of service (DoS) condition on an affected platform.
The vulnerability is due to improper handling of flow base entries by LPTS. This can cause too many known entries for a protocol to be created, causing existing or new sessions to be dropped. An attacker could exploit this vulnerability by sending continuous connection attempts to open TCP ports to cause an exhaustion of services. An exploit could allow the attacker to cause a limited DoS condition on an affected platform.
Cisco has released software updates that address this vulnerability. Workarounds tha
Cisco
Cisco IOS XR Software LPTS Denial of Service Vulnerability
vendor_cisco
CVE-2016-1407 Cisco IOS XR Software LPTS Denial of Service Vulnerability
CVE-2016-1407: Cisco IOS XR Software LPTS Denial of Service Vulnerability
A vulnerability in the Local Packet Transport Services (LPTS) network stack of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a limited denial of service (DoS) condition on an affected platform. The vulnerability is due to improper handling of flow base entries by LPTS. This can cause too many known entries for a protocol to be created, causing existing or new sessions to be dropped. An attacker could exploit this vulnerability by sending continuous connection attempts to open TCP ports to cause an exhaustion of services. An exploit could allow the attacker to cause a limited DoS condition on an affected platform. Cisco has released software updates that address this vulnerability.
CWE
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2016-05-25
Published