First published: Sun Sep 18 2016(Updated: )
Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packets, aka Bug ID CSCuz66289.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 | =6.0.0 | |
Cisco IOS XRv 9000 | =6.0.1 | |
Cisco IOS XRv 9000 | =6.0_base |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1433 is classified as a denial of service vulnerability that can impact Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices.
To mitigate CVE-2016-1433, upgrade to a fixed version of Cisco IOS XR beyond 6.0.1 as recommended by Cisco's security advisory.
CVE-2016-1433 allows remote attackers to send crafted OSPFv3 packets that cause the OSPFv3 process to reload.
CVE-2016-1433 affects Cisco NCS 6000 devices running Cisco IOS XR versions 6.0.0 and 6.0.1.
Yes, CVE-2016-1433 can be exploited remotely without authentication by sending malicious OSPFv3 packets.