CVE-2016-6368 is a denial-of-service vulnerability in Cisco Firepower System Software, affecting various Cisco security products, including ASA FirePOWER Services and Firepower appliances. It stems from improper input validation of Pragmatic General Multicast (PGM) protocol packets, allowing an unauthenticated, remote attacker to crash the Snort process. With a CVSS score of 8.6 (HIGH), this vulnerability has a low attack complexity and can lead to a complete denial of service by bypassing traffic inspection or dropping traffic. While there is no known public exploit code or active exploitation, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.0.0:*:*:*:*:*:*:* | ||
6.0.0.0CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.0.0.0:*:*:*:*:*:*:* | ||
6.0.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.0.0.1:*:*:*:*:*:*:* | ||
6.0.1CPE matchmatch criteria | cpe:2.3:a:cisco:secure_firewall_management_center:6.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.