CVE-2016-1370 describes a denial-of-service vulnerability in Cisco Prime Network Analysis Module (NAM) versions prior to 6.2(1-b). The flaw stems from an incorrect calculation of IPv6 payload lengths, allowing remote attackers to crash the 'mond' process and disrupt monitoring services by sending specially crafted IPv6 packets. With a CVSS score of 5.3 (Medium), this vulnerability is network-exploitable with low attack complexity, requiring no user interaction or privileges, and primarily impacts availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:o:cisco:network_analysis_module_software:4.0.0:*:*:*:*:*:*:* | ||
4.1.0CPE matchmatch criteria | cpe:2.3:o:cisco:network_analysis_module_software:4.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.