CVE Vulnerabilities

CVE-2016-1349

Published: Mar 26, 2016 | Modified: Dec 03, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
7.8 HIGH
AV:N/AC:L/Au:N/C:N/I:N/A:C
RedHat/V2
RedHat/V3
Ubuntu

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.

Affected Software

Name Vendor Start Version End Version
Ios_xe Cisco 3.2ja_3.2.0ja (including) 3.2ja_3.2.0ja (including)
Ios_xe Cisco 3.2se_3.2.0se (including) 3.2se_3.2.0se (including)
Ios_xe Cisco 3.2se_3.2.1se (including) 3.2se_3.2.1se (including)
Ios_xe Cisco 3.2se_3.2.2se (including) 3.2se_3.2.2se (including)
Ios_xe Cisco 3.2se_3.2.3se (including) 3.2se_3.2.3se (including)
Ios_xe Cisco 3.3se_3.3.0se (including) 3.3se_3.3.0se (including)
Ios_xe Cisco 3.3se_3.3.1se (including) 3.3se_3.3.1se (including)
Ios_xe Cisco 3.3se_3.3.2se (including) 3.3se_3.3.2se (including)
Ios_xe Cisco 3.3se_3.3.3se (including) 3.3se_3.3.3se (including)
Ios_xe Cisco 3.3se_3.3.4se (including) 3.3se_3.3.4se (including)
Ios_xe Cisco 3.3se_3.3.5se (including) 3.3se_3.3.5se (including)
Ios_xe Cisco 3.3xo_3.3.0xo (including) 3.3xo_3.3.0xo (including)
Ios_xe Cisco 3.3xo_3.3.1xo (including) 3.3xo_3.3.1xo (including)
Ios_xe Cisco 3.3xo_3.3.2xo (including) 3.3xo_3.3.2xo (including)
Ios_xe Cisco 3.4sg_3.4.0sg (including) 3.4sg_3.4.0sg (including)
Ios_xe Cisco 3.4sg_3.4.1sg (including) 3.4sg_3.4.1sg (including)
Ios_xe Cisco 3.4sg_3.4.2sg (including) 3.4sg_3.4.2sg (including)
Ios_xe Cisco 3.4sg_3.4.3sg (including) 3.4sg_3.4.3sg (including)
Ios_xe Cisco 3.4sg_3.4.4sg (including) 3.4sg_3.4.4sg (including)
Ios_xe Cisco 3.4sg_3.4.5sg (including) 3.4sg_3.4.5sg (including)
Ios_xe Cisco 3.4sg_3.4.6sg (including) 3.4sg_3.4.6sg (including)
Ios_xe Cisco 3.5e_3.5.0e (including) 3.5e_3.5.0e (including)
Ios_xe Cisco 3.5e_3.5.1e (including) 3.5e_3.5.1e (including)
Ios_xe Cisco 3.5e_3.5.2e (including) 3.5e_3.5.2e (including)
Ios_xe Cisco 3.5e_3.5.3e (including) 3.5e_3.5.3e (including)
Ios_xe Cisco 3.6e_3.6.0e (including) 3.6e_3.6.0e (including)
Ios_xe Cisco 3.6e_3.6.1e (including) 3.6e_3.6.1e (including)
Ios_xe Cisco 3.6e_3.6.2ae (including) 3.6e_3.6.2ae (including)
Ios_xe Cisco 3.6e_3.6.2e (including) 3.6e_3.6.2e (including)
Ios_xe Cisco 3.7e_3.7.0e (including) 3.7e_3.7.0e (including)
Ios_xe Cisco 3.7e_3.7.1e (including) 3.7e_3.7.1e (including)
Ios_xe Cisco 3.7e_3.7.2e (including) 3.7e_3.7.2e (including)
Core_i5-9400f_firmware Intel - (including) - (including)
Jr6150_firmware Netgear * 2017-01-06 (excluding)
X14j_firmware Samsung t-ms14jakucb-1102.5 (including) t-ms14jakucb-1102.5 (including)
Opensolaris Sun snv_124 (including) snv_124 (including)
Gs1900-10hp_firmware Zyxel * 2.50(aazi.0)c0 (excluding)
Keymouse_firmware Zzinc 3.08 (including) 3.08 (including)

References