CVE-2016-1426
published 2016-07-15CVE-2016-1426: Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.94%
78.0th percentile
Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
| cisco | ios_xr_for_ncs_6000_packet_timer_leak | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vvf-m6gh-56m4: Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2016-1426 [HIGH] GHSA-2vvf-m6gh-56m4: Cisco IOS XR 5
Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.
Cisco
Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
vendor_cisco·2016-07-13·CVSS 7.8
CVE-2016-1426 [HIGH] Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
A vulnerability in the management of system timer resources in Cisco IOS XR for Cisco Network Convergence System 6000 (NCS 6000) Series Routers could allow an unauthenticated, remote attacker to cause a leak of system timer resources, leading to a nonoperational state and an eventual reload of the Route Processor (RP) on the affected platform.
The vulnerability is due to improper management of system timer resources. An attacker could exploit this vulnerability by sending a number of Secure Shell (SSH), Secure Copy Protocol (SCP), and Secure FTP (SFTP) management connections to an affected device. An exploit could allow the attacker to cause a leak of system timer resources, leading to a nonoperational state and
Cisco
Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
vendor_cisco
CVE-2016-1426 Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
CVE-2016-1426: Cisco IOS XR for NCS 6000 Packet Timer Leak Denial of Service Vulnerability
A vulnerability in the management of system timer resources in Cisco IOS XR for Cisco Network Convergence System 6000 (NCS 6000) Series Routers could allow an unauthenticated, remote attacker to cause a leak of system timer resources, leading to a nonoperational state and an eventual reload of the Route Processor (RP) on the affected platform. The vulnerability is due to improper management of system timer resources. An attacker could exploit this vulnerability by sending a number of Secure Shell (SSH), Secure Copy Protocol (SCP), and Secure FTP (SFTP) management connections to an affected device. An exploit could allow the attacker to cause a leak of system timer resources, leading to a nonoperation
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160713-ncs6khttp://www.securityfocus.com/bid/91748http://www.securitytracker.com/id/1036295http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160713-ncs6khttp://www.securityfocus.com/bid/91748http://www.securitytracker.com/id/1036295
2016-07-15
Published