CVE-2016-1351 describes a denial-of-service vulnerability in the Locator/ID Separation Protocol (LISP) implementation within Cisco IOS (versions 15.1 and 15.2) and NX-OS (versions 4.1 through 6.2). A remote unauthenticated attacker can exploit this flaw by sending a specially crafted packet header, leading to a device reload. The vulnerability is rated as High severity (CVSS 7.5), indicating a network-based attack with low complexity, requiring no user interaction, and resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.1\(1\)sy1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(1\)sy1:*:*:*:*:*:*:* | ||
15.1\(1\)sy2CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(1\)sy2:*:*:*:*:*:*:* | ||
15.1\(1\)sy3CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(1\)sy3:*:*:*:*:*:*:* | ||
15.1\(1\)sy4CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(1\)sy4:*:*:*:*:*:*:* | ||
15.1\(1\)sy5CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.1\(1\)sy5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.