CVE-2016-6380
published 2016-10-05CVE-2016-6380: The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from…
PriorityP341high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
3.01%
86.0th percentile
The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.
Affected
3335 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:N/AC:M/Au:N/C:P/I:P/A:C
vendor_cisco8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j746-pcj4-2946: The DNS forwarder in Cisco IOS 12
ghsa_unreviewed·2022-05-13
CVE-2016-6380 [HIGH] CWE-20 GHSA-j746-pcj4-2946: The DNS forwarder in Cisco IOS 12
The DNS forwarder in Cisco IOS 12.0 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.15 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (data corruption or device reload) via a crafted DNS response, aka Bug ID CSCup90532.
CISA ICS
Rockwell Automation Stratix 5900
cisa_ics·2017-05-10
Rockwell Automation Stratix 5900
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix 5900
Last RevisedMay 10, 2017
Alert CodeICSA-17-094-04
## CVSS v3 10.0
ATTENTION: Remotely exploitable/low skill level to exploit.
Vendor: Rockwell Automation
Equipment: Stratix 5900
Vulnerabilities: Improper Input Validation, Resource Management Errors, Improper Authentication, Path Traversal.
## REPOSTED INFORMATION
This advisory was originally posted to the NCCIC Portal on April 4, 2017, and is being released to the NCCIC/ICS-CERT web site.
## AFFECTED PRODUCTS
Rockwell Automation reports that these vulnerabilities affect the following Strat
CISA ICS
Rockwell Automation Stratix Denial-of-Service and Memory Leak Vulnerabilities
cisa_ics·2016-10-13
Rockwell Automation Stratix Denial-of-Service and Memory Leak Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Denial-of-Service and Memory Leak Vulnerabilities
Last RevisedOctober 13, 2016
Alert CodeICSA-16-287-04
## OVERVIEW
Rockwell Automation reports that several of the vulnerabilities contained in Cisco’s semi-annual Cisco IOS and IOS XE Software Security Advisory Bundled PublicationCisco Event Response: September 2016 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication, https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56513, web site last accessed October 13, 2016. could also affect Rockwell Automation’s Allen-Brad
Cisco
Cisco IOS and IOS XE Software DNS Forwarder Denial of Service Vulnerability
vendor_cisco·2016-09-28·CVSS 8.3
CVE-2016-6380 [HIGH] CWE-20 Cisco IOS and IOS XE Software DNS Forwarder Denial of Service Vulnerability
Cisco IOS and IOS XE Software DNS Forwarder Denial of Service Vulnerability
A vulnerability in the DNS forwarder functionality of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, corrupt the information present in the device's local DNS cache, or read part of the process memory.
The vulnerability is due to a flaw in handling crafted DNS response messages. An attacker could exploit this vulnerability by intercepting and crafting a DNS response message to a client DNS query that was forwarded from the affected device to a DNS server. A successful exploit could cause the device to reload, resulting in a denial of service (DoS) condition or corruption of the local DNS cache information.
Cisco has released software updates that addr
Cisco
Cisco IOS and IOS XE Software DNS Forwarder Denial of Service Vulnerability
vendor_cisco
CVE-2016-6380 Cisco IOS and IOS XE Software DNS Forwarder Denial of Service Vulnerability
CVE-2016-6380: Cisco IOS and IOS XE Software DNS Forwarder Denial of Service Vulnerability
A vulnerability in the DNS forwarder functionality of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, corrupt the information present in the device's local DNS cache, or read part of the process memory. The vulnerability is due to a flaw in handling crafted DNS response messages. An attacker could exploit this vulnerability by intercepting and crafting a DNS response message to a client DNS query that was forwarded from the affected device to a DNS server. A successful exploit could cause the device to reload, resulting in a denial of service (DoS) condition or corruption of the local DNS cache information. Cisco has released software updat
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-dnshttp://www.securityfocus.com/bid/93201http://www.securitytracker.com/id/1036914https://ics-cert.us-cert.gov/advisories/ICSA-16-287-04http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-dnshttp://www.securityfocus.com/bid/93201http://www.securitytracker.com/id/1036914https://ics-cert.us-cert.gov/advisories/ICSA-16-287-04
2016-10-05
Published