CVE-2016-1349: Cisco IOS XE

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.

Affected products

  • Cisco IOS XE: version 3.2ja_3.2.0ja only; version 3.2se_3.2.0se only; version 3.2se_3.2.1se only; version 3.2se_3.2.2se only; version 3.2se_3.2.3se only; version 3.3se_3.3.0se only; …
  • Intel Core i5-9400f Firmware: affected versions not specified
  • NETGEAR JR6150 Firmware: before 2017-01-06 (fixed in 2017-01-06)
  • Samsung x14j Firmware: version t-ms14jakucb-1102.5 only
  • Sun Opensolaris: version snv_124 only
  • Zyxel GS1900-10hp Firmware: before 2.50\(aazi.0\)c0 (fixed in 2.50\(aazi.0\)c0)
  • Zzinc Keymouse Firmware: version 3.08 only

Published 2016-03-26. Last modified 2026-06-17.