CVE-2016-6455

CWE-3995 documents5 sources
Severity
7.5HIGH
EPSS
1.2%
top 20.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 3
Latest updateMay 17

Description

A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could allow an unauthenticated, remote attacker to cause a subset of the subscriber sessions to be disconnected, resulting in a partial denial of service (DoS) condition. This vulnerability affects Cisco ASR 5500 devices with Data Processing Card 2 (DPC2) running StarOS 18.0 or later. More Information: CSCvb12081. Known Affected Releases: 18.7.4 19.5.0 20.0.2.64048 20.2.3 21.0.0. Known

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5cisco_staros_18.x_through_21.xCisco StarOS 18.x through 21.x
NVDcisco/asr_5000_software21 versions+20

🔴Vulnerability Details

2
GHSA
GHSA-c5xh-8h52-w9w3: A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could allow an unauthenticated, remote2022-05-17
CVEList
CVE-2016-6455: A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could allow an unauthenticated, remote2016-11-03

📋Vendor Advisories

1
Cisco
Cisco ASR 5500 Series with DPC2 Cards SESSMGR Denial of Service Vulnerability2016-11-02

💬Community

1
Bugzilla
CVE-2016-1000025 nodejs-ws: DoS due to excessively large websocket message2016-06-29