First published: Thu Jun 23 2016(Updated: )
Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug ID CSCux13174.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XE Web UI | =3.15.0s | |
Cisco IOS XE Web UI | =3.16.0s | |
Cisco IOS XE Web UI | =3.17.0s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1428 has a severity level that indicates it could lead to a denial of service by causing device restarts.
To fix CVE-2016-1428, you should upgrade Cisco IOS XE to a version that is not affected by this vulnerability.
Remote authenticated users can exploit CVE-2016-1428 in the affected Cisco IOS XE versions 3.15S, 3.16S, and 3.17S.
The impact of CVE-2016-1428 is a potential denial of service, leading to unexpected restarts of the affected devices.
CVE-2016-1428 was disclosed on June 20, 2016, as part of a Cisco Security Advisory.