PT-2016-6868 · Cisco · Cisco Ios Xe+1
Published
2016-09-28
·
Updated
2017-11-08
·
CVE-2016-6392
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Cisco IOS versions 12.2 and 15.0 through 15.3
Cisco IOS XE versions 3.1 through 3.9
Description
Multiple vulnerabilities in the multicast subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition. The issues are in IPv4 Multicast Source Discovery Protocol (MSDP) and IPv6 Protocol Independent Multicast (PIM). An attacker who can send traffic to the IPv4 address of a device could exploit this vulnerability by sending a packet designed to trigger the issue to the affected device. A successful exploit could cause the affected device to restart.
Recommendations
For Cisco IOS versions 12.2 and 15.0 through 15.3, update to a newer version that addresses these vulnerabilities.
For Cisco IOS XE versions 3.1 through 3.9, update to a newer version that addresses these vulnerabilities.
As a temporary workaround, consider restricting access to the MSDP and PIM protocols to minimize the risk of exploitation.
At the moment, there is no information about other workarounds that address these vulnerabilities.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios
Cisco Ios Xe