CVE-2016-1367 describes a denial-of-service vulnerability in Cisco Adaptive Security Appliance (ASA) Software version 9.4.1. Specifically, the DHCPv6 relay implementation can be exploited by remote attackers sending crafted DHCPv6 packets, leading to a device reload. This vulnerability has a CVSS v3 score of 7.5 (HIGH), indicating it is easily exploitable over the network with no user interaction, resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Despite some community discussion and media coverage, its EPSS score suggests a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.4.1CPE matchmatch criteria | cpe:2.3:o:cisco:adaptive_security_appliance_software:9.4.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.