CVE-2016-1428
published 2016-06-23CVE-2016-1428: Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a…
PriorityP430medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.18%
64.6th percentile
Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug ID CSCux13174.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
| cisco | ios_xe | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
vendor_cisco6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XE Software SNMP Subsystem Denial of Service Vulnerability
vendor_cisco·2016-06-20·CVSS 6.8
CVE-2016-1428 [MEDIUM] CWE-399 Cisco IOS XE Software SNMP Subsystem Denial of Service Vulnerability
Cisco IOS XE Software SNMP Subsystem Denial of Service Vulnerability
A vulnerability in the SNMP subsystem of Cisco IOS XE software could allow an authenticated, remote attacker to create a denial of service (DoS) condition.
The vulnerability is due to an attempt to double free a region of memory when processing a series of SNMP read requests that contains certain criteria for a specific object ID (OID). An attacker who can authenticate to an affected device may submit a series of valid but specially formed SNMP requests designed to trigger the vulnerability. Successful exploitation will cause the device to restart because of an attempt to access an invalid memory region.
Cisco has released software updates that address this vulnerability. Workarounds that mitigate this vulnerability ar
Cisco
Cisco IOS XE Software SNMP Subsystem Denial of Service Vulnerability
vendor_cisco
CVE-2016-1428 Cisco IOS XE Software SNMP Subsystem Denial of Service Vulnerability
CVE-2016-1428: Cisco IOS XE Software SNMP Subsystem Denial of Service Vulnerability
A vulnerability in the SNMP subsystem of Cisco IOS XE software could allow an authenticated, remote attacker to create a denial of service (DoS) condition. The vulnerability is due to an attempt to double free a region of memory when processing a series of SNMP read requests that contains certain criteria for a specific object ID (OID). An attacker who can authenticate to an affected device may submit a series of valid but specially formed SNMP requests designed to trigger the vulnerability. Successful exploitation will cause the device to restart because of an attempt to access an invalid memory region. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCu
GHSA
GHSA-8wv6-5hv9-2fh8: Double free vulnerability in Cisco IOS XE 3
ghsa_unreviewed·2022-05-17
CVE-2016-1428 [MEDIUM] GHSA-8wv6-5hv9-2fh8: Double free vulnerability in Cisco IOS XE 3
Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug ID CSCux13174.
No detection rules found.
No public exploits indexed.
2016-06-23
Published