CVE-2016-6409
published 2016-09-24CVE-2016-6409: The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.60%
73.3th percentile
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios_and_ios_xe | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_cisco4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS and IOS XE Software Data in Motion Component Denial of Service Vulnerability
vendor_cisco·2016-09-21·CVSS 4.3
CVE-2016-6409 [MEDIUM] CWE-399 Cisco IOS and IOS XE Software Data in Motion Component Denial of Service Vulnerability
Cisco IOS and IOS XE Software Data in Motion Component Denial of Service Vulnerability
A vulnerability in the Cisco Data in Motion (DMo) component for Cisco IOS and IOS XE Software with the IOx feature set could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition for the DMo process on a targeted system.
The vulnerability is due to insufficient bounds checks by the affected component. An attacker could exploit this vulnerability by sending crafted traffic to a targeted system for processing by the affected component. A successful exploit could allow the attacker to cause a partial DoS condition for the affected component on the targeted system.
Cisco has released software updates that address this vulnerability. There are no workarounds that ad
Cisco
Cisco IOS and IOS XE Software Data in Motion Component Denial of Service Vulnerability
vendor_cisco
CVE-2016-6409 Cisco IOS and IOS XE Software Data in Motion Component Denial of Service Vulnerability
CVE-2016-6409: Cisco IOS and IOS XE Software Data in Motion Component Denial of Service Vulnerability
A vulnerability in the Cisco Data in Motion (DMo) component for Cisco IOS and IOS XE Software with the IOx feature set could allow an unauthenticated, remote attacker to cause a partial denial of service (DoS) condition for the DMo process on a targeted system. The vulnerability is due to insufficient bounds checks by the affected component. An attacker could exploit this vulnerability by sending crafted traffic to a targeted system for processing by the affected component. A successful exploit could allow the attacker to cause a partial DoS condition for the affected component on the targeted system. Cisco has released software updates that address this vulnerability. There are no
CWE: CW
GHSA
GHSA-qxrq-2pff-rhpw: The Data in Motion (DMo) component in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2016-6409 [HIGH] GHSA-qxrq-2pff-rhpw: The Data in Motion (DMo) component in Cisco IOS 15
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-dmohttp://www.securityfocus.com/bid/93094http://www.securitytracker.com/id/1036875http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160921-dmohttp://www.securityfocus.com/bid/93094http://www.securitytracker.com/id/1036875
2016-09-24
Published