CVE-2016-6422 describes a vulnerability in Cisco IOS 12.2(33)SXJ9 on Supervisor Engine 32 and 720 modules for 6500 and 7600 devices. This flaw allows remote attackers to bypass access restrictions by exploiting mishandling of specific operators, flags, and keywords in TCAM share ACLs, enabling packets to bypass intended filters. With a CVSS score of 7.5 (High), the vulnerability is network-exploitable with low attack complexity, requiring no user interaction, and could lead to high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2\(33\)sxj9CPE matchmatch criteria | cpe:2.3:o:cisco:ios:12.2\(33\)sxj9:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.