CVE-2016-1349: High severity cisco ios xe vulnerability
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1349?
CVE-2016-1349 is classified as a high severity vulnerability due to its ability to cause a denial of service by reloading affected devices.
How do I fix CVE-2016-1349?
To mitigate CVE-2016-1349, it is recommended to upgrade to a Cisco IOS or IOS XE version that addresses this vulnerability as detailed in Cisco's security advisory.
Which devices are affected by CVE-2016-1349?
CVE-2016-1349 affects various Cisco IOS and IOS XE versions, specifically 12.2, 15.0, and 15.2, and certain versions of IOS XE 3.2 through 3.7.
What is the impact of exploiting CVE-2016-1349?
Exploitation of CVE-2016-1349 allows remote attackers to send crafted packets that could lead to device reloads, effectively causing a denial of service.
Is there a workaround for CVE-2016-1349?
A temporary workaround for CVE-2016-1349 includes disabling the Smart Install feature on affected devices until the software is updated.