Lucene search

K
cveCiscoCVE-2016-1478
HistoryAug 08, 2016 - 12:59 a.m.

CVE-2016-1478

2016-08-0800:59:09
CWE-20
cisco
web.nvd.nist.gov
26
cisco
ios
ntp
denial of service
cve-2016-1478
bug id cscva35619
security vulnerability

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

High

EPSS

0.006

Percentile

77.8%

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.

Affected configurations

Nvd
Node
ciscoiosMatch15.5\(3\)s3
OR
ciscoiosMatch15.6\(1\)s2
OR
ciscoiosMatch15.6\(2\)s1
OR
ciscoiosMatch15.6\(2\)t1
VendorProductVersionCPE
ciscoios15.5(3)s3cpe:2.3:o:cisco:ios:15.5\(3\)s3:*:*:*:*:*:*:*
ciscoios15.6(1)s2cpe:2.3:o:cisco:ios:15.6\(1\)s2:*:*:*:*:*:*:*
ciscoios15.6(2)s1cpe:2.3:o:cisco:ios:15.6\(2\)s1:*:*:*:*:*:*:*
ciscoios15.6(2)t1cpe:2.3:o:cisco:ios:15.6\(2\)t1:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.3

Confidence

High

EPSS

0.006

Percentile

77.8%