CVE-2016-1407: Cisco IOS XR

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.

Affected products

  • Cisco IOS XR: version 2.0.0 only; version 3.0.0 only; version 3.0.1 only; version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; …

Published 2016-05-25. Last modified 2026-06-17.