CVE-2016-10142 describes a vulnerability in the IPv6 protocol specification related to ICMP Packet Too Big (PTB) messages, affecting all IPv6 implementations. An attacker can exploit this by sending a forged ICMPv6 PTB message to trigger the generation of IPv6 atomic fragments, even when not needed. This can lead to a Denial of Service (DoS) by causing legitimate traffic to be dropped by intermediate nodes or ACLs that filter fragmented packets. With a CVSS score of 8.6 (High), the attack is network-based, low complexity, and requires no user interaction, resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:ietf:ipv6:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.