CVE-2016-6385
published 2016-10-05CVE-2016-6385: Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.28%
87.2th percentile
Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.
Affected
191 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jh8r-mwhp-fvw6: Memory leak in the Smart Install client implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2016-6385 [HIGH] GHSA-jh8r-mwhp-fvw6: Memory leak in the Smart Install client implementation in Cisco IOS 12
Memory leak in the Smart Install client implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.2 through 3.8 allows remote attackers to cause a denial of service (memory consumption) via crafted image-list parameters, aka Bug ID CSCuy82367.
CISA ICS
Rockwell Automation Stratix Denial-of-Service and Memory Leak Vulnerabilities
cisa_ics·2016-10-13
Rockwell Automation Stratix Denial-of-Service and Memory Leak Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Rockwell Automation Stratix Denial-of-Service and Memory Leak Vulnerabilities
Last RevisedOctober 13, 2016
Alert CodeICSA-16-287-04
## OVERVIEW
Rockwell Automation reports that several of the vulnerabilities contained in Cisco’s semi-annual Cisco IOS and IOS XE Software Security Advisory Bundled PublicationCisco Event Response: September 2016 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication, https://tools.cisco.com/security/center/viewErp.x?alertId=ERP-56513, web site last accessed October 13, 2016. could also affect Rockwell Automation’s Allen-Brad
Cisco
Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
vendor_cisco·2016-09-28·CVSS 7.8
CVE-2016-6385 [HIGH] CWE-399 Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
The Smart Install client feature in Cisco IOS and IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a memory leak and eventual denial of service (DoS) condition on an affected device.
The vulnerability is due to incorrect handling of image list parameters. An attacker could exploit this vulnerability by sending crafted Smart Install packets to TCP port 4786. A successful exploit could cause a Cisco Catalyst switch to leak memory and eventually reload, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability other than disabling Smart Install functionality on the affecte
Cisco
Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
vendor_cisco
CVE-2016-6385 Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
CVE-2016-6385: Cisco IOS and IOS XE Software Smart Install Memory Leak Vulnerability
The Smart Install client feature in Cisco IOS and IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to cause a memory leak and eventual denial of service (DoS) condition on an affected device. The vulnerability is due to incorrect handling of image list parameters. An attacker could exploit this vulnerability by sending crafted Smart Install packets to TCP port 4786. A successful exploit could cause a Cisco Catalyst switch to leak memory and eventually reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCuy82367, CSCtj75729, CSCtj75729
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-smihttp://www.securityfocus.com/bid/93203http://www.securitytracker.com/id/1036914https://ics-cert.us-cert.gov/advisories/ICSA-16-287-04http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-smihttp://www.securityfocus.com/bid/93203http://www.securitytracker.com/id/1036914https://ics-cert.us-cert.gov/advisories/ICSA-16-287-04
2016-10-05
Published