CVE-2016-6384: Input Validation
Published Oct 5, 2016
·Updated
Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device reload) via crafted fields in an H.323 message, aka Bug ID CSCux04257.
Affected Software
4 affected components
cisco IOS>=12.2<=12.4
cisco IOS>=15.0<=15.6
Cisco IOS XE>=3.1<=3.17
Cisco IOS XE=16.2
Event History
Oct 5, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6384?
CVE-2016-6384 has a high severity rating as it allows remote attackers to cause a denial of service by triggering device reloads.
2
How do I fix CVE-2016-6384?
To fix CVE-2016-6384, update your Cisco IOS or IOS XE software to a version that is not affected by this vulnerability.
3
Which devices are affected by CVE-2016-6384?
CVE-2016-6384 affects Cisco IOS versions 12.2 to 12.4 and 15.0 to 15.6, as well as IOS XE versions 3.1 to 3.17 and specifically 16.2.
4
What type of vulnerability is CVE-2016-6384?
CVE-2016-6384 is classified as a denial of service vulnerability.
5
Can CVE-2016-6384 be exploited remotely?
Yes, CVE-2016-6384 can be exploited remotely via crafted fields in H.323 messages.