CVE-2016-1344: High severity cisco ios xe vulnerability
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1344?
CVE-2016-1344 has been classified as a high severity vulnerability due to its potential to cause a denial of service by triggering device reloads.
How do I fix CVE-2016-1344?
To address CVE-2016-1344, you should upgrade your Cisco IOS or IOS XE software to a version that includes the relevant security patches.
What systems are affected by CVE-2016-1344?
CVE-2016-1344 affects Cisco IOS versions 15.0 through 15.6 and Cisco IOS XE versions 3.3 through 3.17.
What type of attack does CVE-2016-1344 enable?
CVE-2016-1344 allows remote attackers to exploit fragmented packets to cause a denial of service.
Is there a workaround for CVE-2016-1344?
There are no specific workarounds for CVE-2016-1344; upgrading to a fixed version is the recommended approach.