CVE-2016-1454: Input Validation
Cisco NX-OS 4.0 through 7.3 and 11.0 through 11.2 on 1000v, 2000, 3000, 3500, 5000, 5500, 5600, 6000, 7000, 7700, and 9000 devices allows remote attackers to cause a denial of service (device reload) by leveraging a peer relationship to send a crafted BGP UPDATE message, aka Bug IDs CSCuq77105 and CSCux11417.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1454?
CVE-2016-1454 has been assigned a high severity level due to its ability to cause denial of service on vulnerable Cisco NX-OS devices.
How do I fix CVE-2016-1454?
To mitigate CVE-2016-1454, affected users should upgrade to a version of Cisco NX-OS that is not vulnerable, specifically versions above 7.3.
What types of devices are affected by CVE-2016-1454?
CVE-2016-1454 impacts various Cisco Nexus devices, including models from the 1000v series through the 9000 series running affected NX-OS versions.
Can CVE-2016-1454 be exploited remotely?
Yes, CVE-2016-1454 can be exploited remotely by attackers leveraging peer relationships to send crafted BGP UPDATE messages.
What are the potential consequences of CVE-2016-1454?
The exploitation of CVE-2016-1454 can lead to a denial of service, causing the device to reload unexpectedly.