CVE-2016-1478Improper Input Validation in Cisco IOS

Severity
7.5HIGHNVD
EPSS
1.5%
top 18.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 8
Latest updateMay 17

Description

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages1 packages

NVDcisco/ios4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-3q3v-4552-vg2p: Cisco IOS 152022-05-17
CVEList
CVE-2016-1478: Cisco IOS 152016-08-08

📋Vendor Advisories

1
Cisco
Cisco IOS and IOS XE Software Crafted Network Time Protocol Packets Denial of Service Vulnerability2016-08-04
CVE-2016-1478 — Improper Input Validation in Cisco IOS | cvebase