CVE-2016-1350 is a denial-of-service vulnerability affecting Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager. Remote attackers can trigger a device reload by sending malformed SIP messages. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. There is no evidence of active exploitation, nor are there public exploit modules like Metasploit or Nuclei. While there are a few community discussions and media mentions, the vulnerability is not on the CISA KEV catalog or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.8.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.8.0s:*:*:*:*:*:*:* | ||
3.8.1sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.8.1s:*:*:*:*:*:*:* | ||
3.8.2sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.8.2s:*:*:*:*:*:*:* | ||
3.9.0asCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.9.0as:*:*:*:*:*:*:* | ||
3.9.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.9.0s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.