CVE-2016-6403
published 2016-09-18CVE-2016-6403: The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of…
PriorityP426medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
1.60%
73.0th percentile
The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCuy82904, CSCuy82909, and CSCuy82912.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.6\(1\)t | — |
| cisco | ios_and_ios_xe | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x62p-8m89-mwg9: The Data in Motion (DMo) application in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-6403 [MEDIUM] GHSA-x62p-8m89-mwg9: The Data in Motion (DMo) application in Cisco IOS 15
The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCuy82904, CSCuy82909, and CSCuy82912.
Cisco
Cisco IOS and IOS XE Software Data in Motion Denial of Service Vulnerability
vendor_cisco·2016-09-14·CVSS 4.3
CVE-2016-6403 [MEDIUM] CWE-399 Cisco IOS and IOS XE Software Data in Motion Denial of Service Vulnerability
Cisco IOS and IOS XE Software Data in Motion Denial of Service Vulnerability
A vulnerability in the Data in Motion (DMo) application in Cisco IOS and IOS XE software with the IOx feature set could allow an unauthenticated, remote attacker to to cause a denial of service (DoS) condition in the DMo process.
The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by sending a specially crafted packet to the targeted system. An exploit could allow the attacker to cause a DoS condition on the targeted system.
Cisco has released software updates that address this vulnerability. Workarounds that address this vulnerability are not available.
This advisory is available at the following link: https://sec.cloudapps.cisco.com
Cisco
Cisco IOS and IOS XE Software Data in Motion Denial of Service Vulnerability
vendor_cisco
CVE-2016-6403 Cisco IOS and IOS XE Software Data in Motion Denial of Service Vulnerability
CVE-2016-6403: Cisco IOS and IOS XE Software Data in Motion Denial of Service Vulnerability
A vulnerability in the Data in Motion (DMo) application in Cisco IOS and IOS XE software with the IOx feature set could allow an unauthenticated, remote attacker to to cause a denial of service (DoS) condition in the DMo process. The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this vulnerability by sending a specially crafted packet to the targeted system. An exploit could allow the attacker to cause a DoS condition on the targeted system. Cisco has released software updates that address this vulnerability.
CWE: CWE-399, CWE-399
Bug IDs: CSCuy82904, CSCuy82909, CSCuy82912
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160914-ios-xehttp://www.securityfocus.com/bid/92960http://www.securitytracker.com/id/1036833http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160914-ios-xehttp://www.securityfocus.com/bid/92960http://www.securitytracker.com/id/1036833
2016-09-18
Published