CVE-2016-6421
published 2016-10-05CVE-2016-6421: Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID…
PriorityP426medium5.3CVSS 3.0
AVNACLPRNUINSUCNINAL
EPSS
1.60%
73.2th percentile
Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID CSCvb05643.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios_xr | — | — |
| cisco | ios_xr | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_cisco5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS XR Software Open Shortest Path First Link State Advertisement Denial of Service Vulnerability
vendor_cisco·2016-09-28·CVSS 5.0
CVE-2016-6421 [MEDIUM] CWE-399 Cisco IOS XR Software Open Shortest Path First Link State Advertisement Denial of Service Vulnerability
Cisco IOS XR Software Open Shortest Path First Link State Advertisement Denial of Service Vulnerability
A vulnerability in the implementation of Open Shortest Path First (OSPF) Link State Advertisement (LSA) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.
The vulnerability is due to a memory error in OSPF. An attacker could exploit this vulnerability by sending a crafted OSPF LSA update to an affected device. A successful exploit could allow the attacker to cause the OSPF process to restart when the crafted OSPF LSA update is received, resulting in a DoS condition.
Cisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This adv
Cisco
Cisco IOS XR Software Open Shortest Path First Link State Advertisement Denial of Service Vulnerability
vendor_cisco
CVE-2016-6421 Cisco IOS XR Software Open Shortest Path First Link State Advertisement Denial of Service Vulnerability
CVE-2016-6421: Cisco IOS XR Software Open Shortest Path First Link State Advertisement Denial of Service Vulnerability
A vulnerability in the implementation of Open Shortest Path First (OSPF) Link State Advertisement (LSA) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a memory error in OSPF. An attacker could exploit this vulnerability by sending a crafted OSPF LSA update to an affected device. A successful exploit could allow the attacker to cause the OSPF process to restart when the crafted OSPF LSA update is received, resulting in a DoS condition. Cisco has not released software updates that address this vulnerability. There are no
CWE: CWE-399, CWE-399
Bug IDs: CSCvb05643
GHSA
GHSA-p9ch-7c57-q9hh: Cisco IOS XR 5
ghsa_unreviewed·2022-05-17
CVE-2016-6421 [MEDIUM] GHSA-p9ch-7c57-q9hh: Cisco IOS XR 5
Cisco IOS XR 5.2.2 allows remote attackers to cause a denial of service (process restart) via a crafted OSPF Link State Advertisement (LSA) update, aka Bug ID CSCvb05643.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-ospfhttp://www.securityfocus.com/bid/93212http://www.securitytracker.com/id/1036909http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160928-ospfhttp://www.securityfocus.com/bid/93212http://www.securitytracker.com/id/1036909
2016-10-05
Published