CVE-2016-1399 is a denial-of-service vulnerability affecting specific Cisco Industrial Ethernet 4000 and 5000 series devices running particular IOS versions. Remote attackers can exploit this flaw by sending specially crafted IPv4 ICMP packets, leading to packet data corruption. With a CVSS v3 score of 7.5 (High), this vulnerability requires no user interaction or authentication, and has a low attack complexity, potentially causing significant disruption. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its presence in industrial control systems warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.2\(2\)ebCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)eb:*:*:*:*:*:*:* | ||
15.2\(2\)eb1CPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)eb1:*:*:*:*:*:*:* | ||
15.2\(2\)ea2CPE matchmatch criteria | cpe:2.3:a:cisco:ios:15.2\(2\)ea2:*:*:*:*:*:*:* | ||
15.2\(4\)eaCPE matchmatch criteria | cpe:2.3:a:cisco:ios:15.2\(4\)ea:*:*:*:*:*:*:* | ||
15.2\(2\)eaCPE matchmatch criteria | cpe:2.3:o:cisco:ios:15.2\(2\)ea:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.