CVE-2016-1347

HIGH

Cisco IOS 15.1-15.5 - Denial of Service via Crafted TCP Segment

Title source: llm
STIX 2.1

Description

The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.

References (2)

Core 2
Core References
Broken Link vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035380

Scores

CVSS v3 7.5
EPSS 0.0149
EPSS Percentile 71.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (33)
cisco/ios 15.1\(4\)gc2
cisco/ios 15.1\(4\)m6
cisco/ios 15.1\(4\)xb4
cisco/ios 15.1\(4\)xb5
cisco/ios 15.1\(4\)xb5a
cisco/ios 15.1\(4\)xb6
cisco/ios 15.1\(4\)xb7
cisco/ios 15.1\(4\)xb8
cisco/ios 15.1\(4\)xb8a
cisco/ios 15.2\(4\)jaz1
... and 23 more
Published Mar 24, 2016
Tracked Since Feb 18, 2026