CVE-2016-1347 describes a denial-of-service vulnerability affecting Cisco IOS versions 15.1 through 15.5, specifically within the Wide Area Application Services (WAAS) Express implementation. A remote attacker can exploit this by sending a specially crafted TCP segment, leading to a device reload. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in a complete loss of availability. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.1\(4\)gc2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(4\)gc2:*:*:*:*:*:*:* | ||
15.1\(4\)m6CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(4\)m6:*:*:*:*:*:*:* | ||
15.1\(4\)xb4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(4\)xb4:*:*:*:*:*:*:* | ||
15.1\(4\)xb5CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(4\)xb5:*:*:*:*:*:*:* | ||
15.1\(4\)xb5aCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(4\)xb5a:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.