CVE-2016-1425: Buffer Overflow
Published Jul 3, 2016
·Updated
Cisco IOS 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun66735.
Affected Software
5 affected components
Cisco IOS=15.0\(2\)sg5
Cisco IOS=15.1\(2\)sg3
Cisco IOS=15.2\(1\)e
Cisco IOS=15.3\(3\)s
Cisco IOS=15.4\(1.13\)s
Event History
Jul 3, 2016
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1425?
CVE-2016-1425 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2016-1425?
To fix CVE-2016-1425, it is recommended to upgrade to a non-vulnerable version of Cisco IOS.
3
Which Cisco IOS versions are affected by CVE-2016-1425?
Affected Cisco IOS versions include 15.0(2)SG5, 15.1(2)SG3, 15.2(1)E, 15.3(3)S, and 15.4(1.13)S.
4
What type of attack does CVE-2016-1425 enable?
CVE-2016-1425 enables remote attackers to crash the affected device, resulting in a denial of service.
5
Is there a workaround for CVE-2016-1425?
There are no documented workarounds for CVE-2016-1425; patching or upgrading is necessary to mitigate the risk.