CVE-2016-9205

HIGH

Cisco IOS XR 6.1.1.BASE - Unauthenticated Denial of Service via HTTP 2.0 Request Handling

Title source: llm
STIX 2.1

Description

A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash, resulting in a denial of service (DoS) condition. More Information: CSCvb14425. Known Affected Releases: 6.1.1.BASE. Known Fixed Releases: 6.1.2.6i.MGBL 6.1.22.9i.MGBL 6.2.1.14i.MGBL.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94813

Scores

CVSS v3 7.5
EPSS 0.0159
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-399
Status published
Products (2)
cisco/ios_xr 6.1.1
n/a/Cisco IOS XR Cisco IOS XR
Published Dec 14, 2016
Tracked Since Feb 18, 2026