CVE-2016-1399: Cisco IOS

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 4000 devices and 15.2(2)EB and 15.2(2)EB1 on Industrial Ethernet 5000 devices allows remote attackers to cause a denial of service (packet data corruption) via crafted IPv4 ICMP packets, aka Bug ID CSCuy13431.

Affected products

  • Cisco IOS: version 15.2(2)eb only; version 15.2(2)eb1 only; version 15.2(2)ea2 only; version 15.2(4)ea only; version 15.2(2)ea only; version 15.2(2)ea1 only

Published 2016-05-14. Last modified 2026-06-17.