First published: Tue Aug 23 2016(Updated: )
Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco IOS XRv 9000 | =5.1.0 | |
Cisco IOS XRv 9000 | =5.1.1 | |
Cisco IOS XRv 9000 | =5.1.1.k9sec | |
Cisco IOS XRv 9000 | =5.1.2 | |
Cisco IOS XRv 9000 | =5.1.3 | |
Cisco IOS XRv 9000 | =5.2.0 | |
Cisco IOS XRv 9000 | =5.2.1 | |
Cisco IOS XRv 9000 | =5.2.2 | |
Cisco IOS XRv 9000 | =5.2.3 | |
Cisco IOS XRv 9000 | =5.2.4 | |
Cisco IOS XRv 9000 | =5.2.5 | |
Cisco IOS XRv 9000 | =5.3.0 | |
Cisco IOS XRv 9000 | =5.3.1 | |
Cisco IOS XRv 9000 | =5.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6355 has been assigned a severity rating that can lead to a denial of service condition.
To address CVE-2016-6355, update Cisco IOS XR to a version that is not affected, specifically versions 5.1.4, 5.2.6, and 5.3.3 or later.
CVE-2016-6355 affects Cisco ASR 9001 devices running specific versions of Cisco IOS XR.
CVE-2016-6355 can be exploited by remote attackers using crafted fragmented packets to cause control-plane protocol outages.
There are no specific workarounds for CVE-2016-6355; the recommended action is to apply the appropriate software updates.