CVE-2016-1407: Input Validation
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1407?
CVE-2016-1407 has been classified with a severity rating that indicates it can lead to a denial of service condition.
How do I fix CVE-2016-1407?
To fix CVE-2016-1407, it is recommended to upgrade to a patched version of Cisco IOS XR that addresses this vulnerability.
Which versions of Cisco IOS XR are affected by CVE-2016-1407?
CVE-2016-1407 affects Cisco IOS XR versions through 5.3.2.
What are the potential impacts of CVE-2016-1407?
The potential impacts of CVE-2016-1407 include remote attackers being able to cause session drops through excessive connection attempts.
Is there a known exploit for CVE-2016-1407?
Yes, CVE-2016-1407 is known to be potentially exploitable by remote attackers to achieve a denial of service.