CVE-2016-1426: High severity cisco network convergence system 6000 vulnerability
Published Jul 15, 2016
·Updated
Cisco IOS XR 5.x through 5.2.5 on NCS 6000 devices allows remote attackers to cause a denial of service (timer consumption and Route Processor reload) via crafted SSH traffic, aka Bug ID CSCux76819.
Affected Software
15 affected components
Cisco Network Convergence System 6000
Cisco IOS XR=5.0.0
Cisco IOS XR=5.0.1
Cisco IOS XR=5.0_base
Cisco IOS XR=5.1.0
Cisco IOS XR=5.1.1
Cisco IOS XR=5.1.1.k9sec
Cisco IOS XR=5.1.2
Cisco IOS XR=5.1.3
Cisco IOS XR=5.2.0
Cisco IOS XR=5.2.1
Cisco IOS XR=5.2.2
Cisco IOS XR=5.2.3
Cisco IOS XR=5.2.4
Cisco IOS XR=5.2.5
Event History
Jul 15, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1426?
CVE-2016-1426 has a critical severity level due to its potential to cause denial of service on affected Cisco devices.
2
How do I fix CVE-2016-1426?
To fix CVE-2016-1426, update Cisco IOS XR to version 5.2.6 or later, which addresses this vulnerability.
3
What devices are affected by CVE-2016-1426?
CVE-2016-1426 affects Cisco IOS XR versions from 5.0.0 to 5.2.5 on NCS 6000 devices.
4
What type of attack does CVE-2016-1426 involve?
CVE-2016-1426 involves a remote denial of service attack through crafted SSH traffic.
5
Can CVE-2016-1426 lead to data loss?
While CVE-2016-1426 primarily leads to denial of service, it does not directly cause data loss, but service disruption may affect data accessibility.