CVE-2016-1376: Input Validation
Published Apr 12, 2016
·Updated
Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548.
Affected Software
4 affected components
Cisco IOS XR=4.2.3
Cisco IOS XR=4.3.0
Cisco IOS XR=4.3.4
Cisco IOS XR=5.3.1
Event History
Apr 12, 2016
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1376?
CVE-2016-1376 is classified as a denial of service vulnerability.
2
How do I fix CVE-2016-1376?
The recommended fix for CVE-2016-1376 is to upgrade affected Cisco IOS XR versions to a patched version provided by Cisco.
3
What devices are affected by CVE-2016-1376?
CVE-2016-1376 affects Cisco ASR 9000 devices running specific versions of Cisco IOS XR.
4
What types of attacks exploit CVE-2016-1376?
CVE-2016-1376 can be exploited by remote attackers sending crafted packets that cause denial of service.
5
What versions of Cisco IOS XR are vulnerable in CVE-2016-1376?
CVE-2016-1376 affects Cisco IOS XR versions 4.2.3, 4.3.0, 4.3.4, and 5.3.1.