cbcvebase.
CVE-2016-1409
published 2016-05-29

CVE-2016-1409: The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote…

PriorityP274high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
3.82%
88.9th percentile
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.

Affected

4892 ranges· showing 25
VendorProductVersion rangeFixed in
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios
ciscoios

Detection & IOCsextracted from sources · hover to see the quote

  • Detect crafted IPv6 Neighbor Discovery (ND) packets sent to network devices; monitor for sudden cessation of IPv6 traffic processing on Cisco IOS XE, IOS XR, or NX-OS devices, which may indicate active exploitation.
  • This vulnerability was exploited in the wild in May 2016; prioritize detection on devices running Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS.
  • Scope is not Cisco-specific; any IPv6 processing unit unable to drop malformed ND packets early in the processing path or in hardware is vulnerable — broaden detection to non-Cisco IPv6 devices as well.
  • ·Affected Cisco IOS XE versions are 2.1 through 3.17S; ensure devices outside this range are still assessed as the vulnerability may affect other IPv6 implementations.
  • ·Multiple Cisco Bug IDs are associated with this vulnerability across different platforms (IOS XE, IOS XR, NX-OS): CSCuz66542, CSCuz79330, CSCuz80276 — use these to track patch status per platform.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vulncheck7.5HIGH
vendor_cisco5.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.