CVE-2016-1436: Buffer Overflow
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager process restart) via a crafted GTPv1 packet, aka Bug ID CSCuz46198.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1436?
CVE-2016-1436 has a severity rating that allows remote attackers to cause a denial of service on affected Cisco ASR 5000 devices.
How do I fix CVE-2016-1436?
To fix CVE-2016-1436, update your Cisco ASR 5000 software to a fixed version provided by Cisco.
What devices are affected by CVE-2016-1436?
CVE-2016-1436 affects Cisco ASR 5000 Packet Data Network Gateway devices running specific versions of the software prior to 19.4.
What impact does CVE-2016-1436 have?
The impact of CVE-2016-1436 can result in a session manager process restart leading to service interruption.
How can I determine if my Cisco ASR 5000 is vulnerable to CVE-2016-1436?
You can determine vulnerability to CVE-2016-1436 by checking the software version against the affected versions listed in the vulnerability details.