CVE-2016-1361: Medium severity cisco ios xrv 9000 vulnerability
Cisco IOS XR through 4.3.2 on Gigabit Switch Router (GSR) 12000 devices does not properly check for a Bidirectional Forwarding Detection (BFD) header in a UDP packet, which allows remote attackers to cause a denial of service (line-card restart) via a crafted packet, aka Bug ID CSCuw56900.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1361?
CVE-2016-1361 has a severity rating of high due to its potential to cause a denial of service.
How do I fix CVE-2016-1361?
To mitigate CVE-2016-1361, it is recommended to upgrade to a fixed version of Cisco IOS XR, specifically 4.3.2 or later.
What devices are impacted by CVE-2016-1361?
CVE-2016-1361 affects Cisco IOS XR versions up to and including 4.3.2 running on Gigabit Switch Router (GSR) 12000 devices.
What kind of attack does CVE-2016-1361 allow?
CVE-2016-1361 allows remote attackers to send crafted packets that can cause line-card restarts.
Is there a workaround for CVE-2016-1361 if I can't upgrade?
There is no recommended workaround for CVE-2016-1361; upgrading to the latest software version is the best course of action.