CVE-2016-1344 is a denial-of-service vulnerability affecting the IKEv2 implementation in Cisco IOS and IOS XE, as well as products from Lenovo, Netgear, Samsung, Sun, Zyxel, and Zzinc. This medium-severity flaw (CVSS 5.9) allows remote, unauthenticated attackers to trigger a device reload by sending specially crafted fragmented packets, though a high attack complexity is noted. There is no evidence of active exploitation, nor are public exploit codes available in Metasploit or ExploitDB. While there's limited community discussion, SecurityWeek reported on Cisco's patches for this and similar DoS flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3s_3.3.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.3s_3.3.0s:*:*:*:*:*:*:* | ||
3.3s_3.3.1sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.3s_3.3.1s:*:*:*:*:*:*:* | ||
3.3s_3.3.2sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.3s_3.3.2s:*:*:*:*:*:*:* | ||
3.3sg_3.3.0sgCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.3sg_3.3.0sg:*:*:*:*:*:*:* | ||
3.3sg_3.3.1sgCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.3sg_3.3.1sg:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Cisco Multiple Routers Fragmented IKEv2 Packet Handling Remote Integer Overflow
Apr 5, 2016[R1] Cisco Multiple Routers Fragmented IKEv2 Packet Handling Remote Integer Overflow
Apr 5, 2016[R1] Cisco Multiple Routers Fragmented IKEv2 Packet Handling Remote Integer Overflow
Apr 5, 2016