CVE-2016-1348: Cisco IOS XE

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.

Affected products

  • Cisco IOS XE: version 3.3xo_3.3.0xo only; version 3.3xo_3.3.1xo only; version 3.3xo_3.3.2xo only; version 3.5e_3.5.0e only; version 3.5e_3.5.1e only; version 3.5e_3.5.2e only; …
  • NETGEAR JR6150 Firmware: before 2017-01-06 (fixed in 2017-01-06)
  • Samsung x14j Firmware: version t-ms14jakucb-1102.5 only
  • Sun Opensolaris: version snv_124 only
  • Zyxel GS1900-10hp Firmware: before 2.50\(aazi.0\)c0 (fixed in 2.50\(aazi.0\)c0)
  • Zzinc Keymouse Firmware: version 3.08 only

Published 2016-03-26. Last modified 2026-06-17.