CVE-2016-1425
published 2016-07-03CVE-2016-1425: Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP…
PriorityP423medium6.5CVSS 3.0
AVAACLPRNUINSUCNINAH
EPSS
0.74%
50.3th percentile
Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun66735.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.1MEDIUMAV:A/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability
vendor_cisco·2016-06-17·CVSS 6.1
CVE-2016-1425 [MEDIUM] CWE-119 Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability
Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) packet processing code of Cisco IOS could allow an unauthenticated, adjacent attacker to cause the crash of an affected device.
The vulnerability is due to improper handling of crafted LLDP packets. An attacker could exploit this vulnerability by sending a specially crafted LLDP packet. An exploit could allow the attacker to cause a Denial of Service (DoS) condition on an affected platform.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurit
Cisco
Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability
vendor_cisco
CVE-2016-1425 Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability
CVE-2016-1425: Cisco IOS Software Link Layer Discovery Protocol Processing Code Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) packet processing code of Cisco IOS could allow an unauthenticated, adjacent attacker to cause the crash of an affected device. The vulnerability is due to improper handling of crafted LLDP packets. An attacker could exploit this vulnerability by sending a specially crafted LLDP packet. An exploit could allow the attacker to cause a Denial of Service (DoS) condition on an affected platform. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-119, CWE-119
Bug IDs: CSCun66735
GHSA
GHSA-6vgp-m9h9-xgw2: Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-1425 [MEDIUM] CWE-119 GHSA-6vgp-m9h9-xgw2: Cisco IOS 15
Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun66735.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/91545http://www.securitytracker.com/id/1036129https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160616-ios1http://www.securityfocus.com/bid/91545http://www.securitytracker.com/id/1036129https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160616-ios1
2016-07-03
Published