First published: Fri Jun 03 2016(Updated: )
Cisco Prime Network Analysis Module (NAM) before 6.2(1-b) miscalculates IPv6 payload lengths, which allows remote attackers to cause a denial of service (mond process crash and monitoring outage) via crafted IPv6 packets, aka Bug ID CSCuy37324.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Network Analysis Module Software | =4.0.0 | |
Cisco Prime Network Analysis Module Software | =4.1.0 | |
Cisco Network Analysis Module Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-1370 is significant as it can lead to denial of service affecting the Cisco Prime Network Analysis Module.
To fix CVE-2016-1370, upgrade to Cisco Prime Network Analysis Module version 6.2(1-b) or later.
CVE-2016-1370 affects Cisco Prime Network Analysis Module versions earlier than 6.2(1-b), specifically 4.0.0 and 4.1.0.
Yes, CVE-2016-1370 can cause monitoring outages due to the crash of the mond process.
Yes, CVE-2016-1370 can be exploited remotely by sending crafted IPv6 packets.