Cisco IOS DoS Vulnerability (CVE-2016-1478)
Cisco IOS DoS Vulnerability (CVE-2016-1478)
Release date:
Updated on:
Affected Systems:
Cisco IOS 15.6 (2) T1
Cisco IOS 15.6 (2) S1
Cisco IOS 15.6 (1) S2
Cisco IOS 15.5 (3) S3
Description:
CVE (CAN) ID: CVE-2016-1478
Cisco IOS is an interconnected network operating system used on most Cisco system routers and network switches.
Cisco IOS 15.5 (3) S3, 15.6 (1) S2, 15.6 (2) S1, 15.6 (2) T1 does not properly process invalid NTP data packets, remote attackers can send a large number of NTP data packets, resulting in DOS.
<* Source: Cisco
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160804-wedge
*>
Suggestion:
Vendor patch:
Cisco
-----
Cisco has released a Security Bulletin (cisco-sa-20160804-wedge) and patches for this:
Cisco-sa-20160804-wedge: Cisco IOS Software Crafted Network Time Protocol Packets Denial of Service Vulnerability
Link: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160804-wedge
This article permanently updates the link address: