CVE-2016-6401: Medium severity cisco crs-3 8-slot single-shelf system vulnerability
Published Sep 17, 2016
·Updated
Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494.
Affected Software
2 affected components
Cisco Carrier Routing System=5.1.4
Cisco Carrier Routing System=5.1_base
Event History
Sep 17, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6401?
CVE-2016-6401 has a severity rating that indicates it could lead to a denial of service condition.
2
How do I fix CVE-2016-6401?
To address CVE-2016-6401, upgrade to a patched version of Cisco Carrier Routing System as advised by Cisco.
3
What types of devices are affected by CVE-2016-6401?
CVE-2016-6401 affects Cisco Carrier Routing System version 5.1 and its variants on CRS-1 and CRS-3 devices.
4
Is CVE-2016-6401 remotely exploitable?
Yes, CVE-2016-6401 can be exploited remotely by sending crafted IPv6-over-MPLS packets.
5
What could happen if CVE-2016-6401 is exploited?
If CVE-2016-6401 is exploited, it can cause line-card reloads, leading to service disruption.