CVE-2016-1349
Last modified
CVE-2016-1349 is a vulnerability of currently unknown severity. The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.. EPSS estimates a 1.98% chance of exploitation in the next 30 days.
Description
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ios Xe | 3.2ja_3.2.0ja |
| Cisco | Ios Xe | 3.2se_3.2.0se |
| Cisco | Ios Xe | 3.2se_3.2.1se |
| Cisco | Ios Xe | 3.2se_3.2.2se |
| Cisco | Ios Xe | 3.2se_3.2.3se |
| Cisco | Ios Xe | 3.3se_3.3.0se |
| Cisco | Ios Xe | 3.3se_3.3.1se |
| Cisco | Ios Xe | 3.3se_3.3.2se |
| Cisco | Ios Xe | 3.3se_3.3.3se |
| Cisco | Ios Xe | 3.3se_3.3.4se |
| Cisco | Ios Xe | 3.3se_3.3.5se |
| Cisco | Ios Xe | 3.3xo_3.3.0xo |
| Cisco | Ios Xe | 3.3xo_3.3.1xo |
| Cisco | Ios Xe | 3.3xo_3.3.2xo |
| Cisco | Ios Xe | 3.4sg_3.4.0sg |
| Cisco | Ios Xe | 3.4sg_3.4.1sg |
| Cisco | Ios Xe | 3.4sg_3.4.2sg |
| Cisco | Ios Xe | 3.4sg_3.4.3sg |
| Cisco | Ios Xe | 3.4sg_3.4.4sg |
| Cisco | Ios Xe | 3.4sg_3.4.5sg |
| Cisco | Ios Xe | 3.4sg_3.4.6sg |
| Cisco | Ios Xe | 3.5e_3.5.0e |
| Cisco | Ios Xe | 3.5e_3.5.1e |
| Cisco | Ios Xe | 3.5e_3.5.2e |
| Cisco | Ios Xe | 3.5e_3.5.3e |
| Cisco | Ios Xe | 3.6e_3.6.0e |
| Cisco | Ios Xe | 3.6e_3.6.1e |
| Cisco | Ios Xe | 3.6e_3.6.2ae |
| Cisco | Ios Xe | 3.6e_3.6.2e |
| Cisco | Ios Xe | 3.7e_3.7.0e |
| Cisco | Ios Xe | 3.7e_3.7.1e |
| Cisco | Ios Xe | 3.7e_3.7.2e |
| Intel | Core I5-9400f Firmware | All versions |
| Netgear | Jr6150 Firmware | < 2017-01-06 |
| Samsung | X14j Firmware | t-ms14jakucb-1102.5 |
| Sun | Opensolaris | snv_124 |
| Zyxel | Gs1900-10hp Firmware | < 2.50\(aazi.0\)c0 |
| Zzinc | Keymouse Firmware | 3.08 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1349?
How severe is CVE-2016-1349?
How do I fix CVE-2016-1349?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1343The XML parser in Cisco Information Server (CIS) 6.2 allows …
- CVE-2016-1344The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and …
- CVE-2016-1345Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA …
- CVE-2016-1346The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18…
- CVE-2016-1347The Wide Area Application Services (WAAS) Express implementa…7.5
- CVE-2016-1348Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allo…
- CVE-2016-1350Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and …
- CVE-2016-1351The Locator/ID Separation Protocol (LISP) implementation in …7.5
- CVE-2016-1352Cisco Unified Computing System (UCS) Central Software 1.3(1b…
- CVE-2016-1353The TCP implementation in Cisco Videoscape Distribution Suit…
- CVE-2016-1354Cross-site scripting (XSS) vulnerability in Cisco Unified Co…
- CVE-2016-1355Cross-site scripting (XSS) vulnerability in the Device Manag…
Are you affected by CVE-2016-1349?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
