CVE-2016-1347: Cisco IOS

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.

Affected products

  • Cisco IOS: version 15.1(4)gc2 only; version 15.1(4)m6 only; version 15.1(4)xb4 only; version 15.1(4)xb5 only; version 15.1(4)xb5a only; version 15.1(4)xb6 only; …

Published 2016-03-24. Last modified 2026-06-17.