CVE-2016-1465 is a denial-of-service vulnerability affecting Cisco Nexus 1000v Application Virtual Switch (AVS) devices running NX-OS, specifically versions prior to 5.2(1)SV3(1.5i). An unauthenticated remote attacker on the same network segment can trigger an ESXi hypervisor crash and purple screen by sending a specially crafted Cisco Discovery Protocol packet, leading to an out-of-bounds memory access. This vulnerability has a CVSSv3 score of 6.5 (Medium), indicating a relatively low attack complexity and requiring network adjacency, but with a high impact on availability. There is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, suggesting it is not actively exploited in the wild. Community discussion and media coverage are minimal, with no mentions or articles, which is typical for the vast majority of CVEs. The EPSS score is very low, further indicating a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0\(4\)sv1\(1\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(4\)sv1\(1\):*:*:*:*:*:*:* | ||
4.0\(4\)sv1\(2\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(4\)sv1\(2\):*:*:*:*:*:*:* | ||
4.0\(4\)sv1\(3\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(4\)sv1\(3\):*:*:*:*:*:*:* | ||
4.0\(4\)sv1\(3a\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(4\)sv1\(3a\):*:*:*:*:*:*:* | ||
4.0\(4\)sv1\(3b\)CPE matchmatch criteria | cpe:2.3:o:cisco:nx-os:4.0\(4\)sv1\(3b\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.