CVE-2016-6392

UnknownEPSS 2.59%

Last modified

CVE-2016-6392 is a vulnerability of currently unknown severity. Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.. EPSS estimates a 2.59% chance of exploitation in the next 30 days.

Description

Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.

Metrics

EPSS Probability
2.59%

83.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CiscoIos12.2\(33\)cx
CiscoIos12.2\(33\)cy
CiscoIos12.2\(33\)cy1
CiscoIos12.2\(33\)ira
CiscoIos12.2\(33\)irb
CiscoIos12.2\(33\)irc
CiscoIos12.2\(33\)ird
CiscoIos12.2\(33\)ire
CiscoIos12.2\(33\)ire1
CiscoIos12.2\(33\)ire2
CiscoIos12.2\(33\)irf
CiscoIos12.2\(33\)irg
CiscoIos12.2\(33\)irg1
CiscoIos12.2\(33\)irh
CiscoIos12.2\(33\)irh1
CiscoIos12.2\(33\)iri
CiscoIos12.2\(33\)mra
CiscoIos12.2\(33\)mrb
CiscoIos12.2\(33\)mrb1
CiscoIos12.2\(33\)mrb2
CiscoIos12.2\(33\)mrb3
CiscoIos12.2\(33\)mrb4
CiscoIos12.2\(33\)mrb5
CiscoIos12.2\(33\)mrb6
CiscoIos12.2\(33\)sb
CiscoIos12.2\(33\)sb1
CiscoIos12.2\(33\)sb2
CiscoIos12.2\(33\)sb3
CiscoIos12.2\(33\)sb4
CiscoIos12.2\(33\)sb5
CiscoIos12.2\(33\)sb6
CiscoIos12.2\(33\)sb7
CiscoIos12.2\(33\)sb8
CiscoIos12.2\(33\)sb9
CiscoIos12.2\(33\)sb10
CiscoIos12.2\(33\)sb11
CiscoIos12.2\(33\)sb12
CiscoIos12.2\(33\)sb13
CiscoIos12.2\(33\)sb14
CiscoIos12.2\(33\)sb15
CiscoIos12.2\(33\)sb16
CiscoIos12.2\(33\)sb17
CiscoIos12.2\(33\)sca
CiscoIos12.2\(33\)sca1
CiscoIos12.2\(33\)sca2
CiscoIos12.2\(33\)scb
CiscoIos12.2\(33\)scb1
CiscoIos12.2\(33\)scb2
CiscoIos12.2\(33\)scb3
CiscoIos12.2\(33\)scb4

Showing 50 of 506 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2016-6392?
Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.
How severe is CVE-2016-6392?
Severity scoring for CVE-2016-6392 is pending analysis. The EPSS model estimates a 2.59% probability of exploitation in the next 30 days.
How do I fix CVE-2016-6392?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2016-6392?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST