CVE-2016-1409
published 2016-05-29CVE-2016-1409: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote…
PriorityP274high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.82%
88.9th percentile
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
Affected
4892 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect crafted IPv6 Neighbor Discovery (ND) packets sent to network devices; monitor for sudden cessation of IPv6 traffic processing on Cisco IOS XE, IOS XR, or NX-OS devices, which may indicate active exploitation. ↗
- →This vulnerability was exploited in the wild in May 2016; prioritize detection on devices running Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS. ↗
- →Scope is not Cisco-specific; any IPv6 processing unit unable to drop malformed ND packets early in the processing path or in hardware is vulnerable — broaden detection to non-Cisco IPv6 devices as well. ↗
- ·Affected Cisco IOS XE versions are 2.1 through 3.17S; ensure devices outside this range are still assessed as the vulnerability may affect other IPv6 implementations. ↗
- ·Multiple Cisco Bug IDs are associated with this vulnerability across different platforms (IOS XE, IOS XR, NX-OS): CSCuz66542, CSCuz79330, CSCuz80276 — use these to track patch status per platform. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
vendor_cisco5.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mmgr-38w5-mg7v: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2
ghsa_unreviewed·2022-05-17
CVE-2016-1409 [HIGH] CWE-20 GHSA-mmgr-38w5-mg7v: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
VulnCheck
Cisco IOS Software Improper Input Validation
vulncheck·2016·CVSS 7.5
CVE-2016-1409 [HIGH] Cisco IOS Software Improper Input Validation
Cisco IOS Software Improper Input Validation
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.
Affected: Cisco IOS Software
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6; https://www.cve.org/CVERecord?id=CVE-2016-1409
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
Cisco
Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability
vendor_cisco·2016-05-25·CVSS 5.8
CVE-2016-1409 [MEDIUM] Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability
Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability
A vulnerability in the IP Version 6 (IPv6) packet processing functions of multiple Cisco products could allow an unauthenticated, remote attacker to cause an affected device to stop processing IPv6 traffic, leading to a denial of service (DoS) condition on the device.
The vulnerability is due to insufficient processing logic for crafted IPv6 packets that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted IPv6 Neighbor Discovery (ND) packets to an affected device for processing. A successful exploit could allow the attacker to cause the device to stop processing IPv6 traffic, leading to a DoS condition on the device.
This vulnerability is not Cisco specific:
Cisco
Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability
vendor_cisco·CVSS 3.0
CVE-2016-1409 Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability
CVE-2016-1409: Cisco Products IPv6 Neighbor Discovery Crafted Packet Denial of Service Vulnerability
A vulnerability in the IP Version 6 (IPv6) packet processing functions of multiple Cisco products could allow an unauthenticated, remote attacker to cause an affected device to stop processing IPv6 traffic, leading to a denial of service (DoS) condition on the device. The vulnerability is due to insufficient processing logic for crafted IPv6 packets that are sent to an affected device. An attacker could exploit this vulnerability by sending crafted IPv6 Neighbor Discovery (ND) packets to an affected device for processing. A successful exploit could allow the attacker to cause the device to stop processing IPv6 traffic, leading to a DoS condition on the device. This vulnerability is not Cisc
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-ipv6-enhttp://www.securityfocus.com/bid/90872http://www.securitytracker.com/id/1035962http://www.securitytracker.com/id/1035963http://www.securitytracker.com/id/1035964http://www.securitytracker.com/id/1035965http://www.securitytracker.com/id/1036651http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160525-ipv6http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160824-01-ipv6-enhttp://www.securityfocus.com/bid/90872http://www.securitytracker.com/id/1035962http://www.securitytracker.com/id/1035963http://www.securitytracker.com/id/1035964http://www.securitytracker.com/id/1035965http://www.securitytracker.com/id/1036651
2016-05-29
Published
Exploited in the wild