CVE-2016-1436

moderate-risk
Published 2016-06-23

The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager process restart) via a crafted GTPv1 packet, aka Bug ID CSCuz46198.

Do I need to act?

-
0.72% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
NETWORK / LOW complexity

Affected Products (20)

Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software
Asr 5000 Software

Affected Vendors

48
/ 100
moderate-risk
Severity 26/34 · High
Exploitability 2/34 · Minimal
Exposure 20/34 · Moderate