National Vulnerability Database

National Vulnerability Database

National Vulnerability
Database

CVE-2016-6455 Detail

Current Description

A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could allow an unauthenticated, remote attacker to cause a subset of the subscriber sessions to be disconnected, resulting in a partial denial of service (DoS) condition. This vulnerability affects Cisco ASR 5500 devices with Data Processing Card 2 (DPC2) running StarOS 18.0 or later. More Information: CSCvb12081. Known Affected Releases: 18.7.4 19.5.0 20.0.2.64048 20.2.3 21.0.0. Known Fixed Releases: 18.7.4 18.7.4.65030 18.8.M0.65044 19.5.0 19.5.0.65092 19.5.M0.65023 19.5.M0.65050 20.2.3 20.2.3.64982 20.2.3.65017 20.2.a4.65307 20.3.M0.64984 20.3.M0.65029 20.3.M0.65037 20.3.M0.65071 20.3.T0.64985 20.3.T0.65031 20.3.T0.65043 20.3.T0.65067 21.0.0 21.0.0.65256 21.0.M0.64922 21.0.M0.64983 21.0.M0.65140 21.0.V0.65150 21.1.A0.64932 21.1.A0.64987 21.1.A0.65145 21.1.PP0.65270 21.1.R0.65130 21.1.R0.65135 21.1.R0.65154 21.1.VC0.65203 21.2.A0.65147.

Source:  MITRE
View Analysis Description

Impact

CVSS v3.0 Severity and Metrics:

Base Score: 7.5 HIGH
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (V3 legend)
Impact Score: 3.6
Exploitability Score: 3.9


Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope (S): Unchanged
Confidentiality (C): None
Integrity (I): None
Availability (A): High

CVSS v2.0 Severity and Metrics:

Base Score: 5.0 MEDIUM
Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P) (V2 legend)
Impact Subscore: 2.9
Exploitability Subscore: 10.0


Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (AU): None
Confidentiality (C): None
Integrity (I): None
Availability (A): Partial
Additional Information:
Allows disruption of service

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

Hyperlink Resource
http://www.securityfocus.com/bid/94071
http://www.securitytracker.com/id/1037186
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161102-asr Vendor Advisory

Technical Details

Vulnerability Type (View All)

  • Resource Management Errors (CWE-399)

Known Affected Software Configurations Switch to CPE 2.3

Configuration 1 ( hide )
 cpe:/o:cisco:asr_5000_software:18.0.0
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.0.0.57828
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.0.0.59167
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.0.0.59211
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.0.l0.59219
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.1.0
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.1.0.59776
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.1.0.59780
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.1_base
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.3.0
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.3_base
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:18.4.0
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.0.1
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.0.m0.60737
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.0.m0.60828
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.0.m0.61045
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.1.0
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.1.0.61559
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.2.0
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:19.3.0
     Show Matching CPE(s)
 cpe:/o:cisco:asr_5000_software:20.0.0
     Show Matching CPE(s)
Running on/with
 cpe:/h:cisco:asr_5500:-
     Show Matching CPE(s)


Change History

5 change records found - show changes

Quick Info

CVE Dictionary Entry:
CVE-2016-6455
NVD Published Date:
11/03/2016
NVD Last Modified:
07/28/2017