CVE-2016-1349 describes a denial-of-service vulnerability in the Smart Install client of Cisco IOS and IOS XE, affecting various Cisco devices. Remote attackers can trigger a device reload by sending crafted Smart Install packets with malicious image list parameters. This vulnerability carries a high CVSS score of 7.5, indicating a severe impact (device reload) with low attack complexity and no user interaction required. While no public exploit code is available and it's not listed in CISA's KEV catalog, the vulnerability has garnered some community discussion and media coverage, though some articles mistakenly link it to a different Cisco vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.2ja_3.2.0jaCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2ja_3.2.0ja:*:*:*:*:*:*:* | ||
3.2se_3.2.0seCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2se_3.2.0se:*:*:*:*:*:*:* | ||
3.2se_3.2.1seCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2se_3.2.1se:*:*:*:*:*:*:* | ||
3.2se_3.2.2seCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2se_3.2.2se:*:*:*:*:*:*:* | ||
3.2se_3.2.3seCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.2se_3.2.3se:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R2] Cisco IOS Smart Install Client Feature Config / Boot Image File List Upload Remote Code Execution
Mar 28, 2016[R2] Cisco IOS Smart Install Client Feature Config / Boot Image File List Upload Remote Code Execution
Mar 28, 2016[R2] Cisco IOS Smart Install Client Feature Config / Boot Image File List Upload Remote Code Execution
Mar 28, 2016