CVE-2016-1347

HIGHCVSS 7.5/10EPSS 1.49%

Last modified

CVE-2016-1347 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.. EPSS estimates a 1.49% chance of exploitation in the next 30 days.

Description

The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.49%

70.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos15.1\(4\)gc2
CiscoIos15.1\(4\)m6
CiscoIos15.1\(4\)xb4
CiscoIos15.1\(4\)xb5
CiscoIos15.1\(4\)xb5a
CiscoIos15.1\(4\)xb6
CiscoIos15.1\(4\)xb7
CiscoIos15.1\(4\)xb8
CiscoIos15.1\(4\)xb8a
CiscoIos15.2\(4\)jaz1
CiscoIos15.2\(4\)m7
CiscoIos15.3\(1\)t2
CiscoIos15.3\(3\)jaa1
CiscoIos15.3\(3\)m
CiscoIos15.3\(3\)m3
CiscoIos15.3\(3\)m4
CiscoIos15.3\(3\)m6
CiscoIos15.4\(1\)t
CiscoIos15.4\(1\)t1
CiscoIos15.4\(1\)t2
CiscoIos15.4\(2\)t
CiscoIos15.4\(2\)t1
CiscoIos15.4\(2\)t2
CiscoIos15.4\(2\)t3
CiscoIos15.4\(2\)t4
CiscoIos15.4\(3\)m
CiscoIos15.4\(3\)m1
CiscoIos15.4\(3\)m2
CiscoIos15.4\(3\)m3
CiscoIos15.5\(2\)t1
CiscoIos15.5\(2\)t2
CiscoIos15.5\(2\)t3
CiscoIos15.5\(3\)m

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-1347?
The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.
How severe is CVE-2016-1347?
CVE-2016-1347 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 1.49% probability of exploitation in the next 30 days.
How do I fix CVE-2016-1347?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-1347?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST