CVE-2016-6441 is a critical vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers running specific versions of Cisco IOS XE Software. An unauthenticated, remote attacker can exploit this to cause a denial of service (reload) or achieve remote code execution on affected systems. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 94/100, the vulnerability is easily exploitable over the network with no user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.17.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.17.0s:*:*:*:*:*:*:* | ||
3.17.1sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.17.1s:*:*:*:*:*:*:* | ||
3.17.2sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.17.2s:*:*:*:*:*:*:* | ||
3.17sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.17s:*:*:*:*:*:*:* | ||
3.18.0sCPE matchmatch criteria | cpe:2.3:o:cisco:ios_xe:3.18.0s:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.