CVE-2016-9205
HIGHCisco IOS XR 6.1.1.BASE - Unauthenticated Denial of Service via HTTP 2.0 Request Handling
Title source: llmDescription
A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. More Information: CSCvb14425. Known Affected Releases: 6.1.1.BASE. Known Fixed Releases: 6.1.2.6i.MGBL 6.1.22.9i.MGBL 6.2.1.14i.MGBL.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161207-ios-xr
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/94813
Scores
CVSS v3
7.5
EPSS
0.0159
EPSS Percentile
73.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-399
Status
published
Products (2)
cisco/ios_xr
6.1.1
n/a/Cisco IOS XR
Cisco IOS XR
Published
Dec 14, 2016
Tracked Since
Feb 18, 2026