CVE-2016-6355: High severity cisco ios xrv 9000 vulnerability
Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6355?
CVE-2016-6355 has been assigned a severity rating that can lead to a denial of service condition.
How do I fix CVE-2016-6355?
To address CVE-2016-6355, update Cisco IOS XR to a version that is not affected, specifically versions 5.1.4, 5.2.6, and 5.3.3 or later.
Which devices are affected by CVE-2016-6355?
CVE-2016-6355 affects Cisco ASR 9001 devices running specific versions of Cisco IOS XR.
What type of attack can exploit CVE-2016-6355?
CVE-2016-6355 can be exploited by remote attackers using crafted fragmented packets to cause control-plane protocol outages.
Is there a workaround for CVE-2016-6355?
There are no specific workarounds for CVE-2016-6355; the recommended action is to apply the appropriate software updates.