CVE-2016-1436: Cisco Asr 5000 Software

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager process restart) via a crafted GTPv1 packet, aka Bug ID CSCuz46198.

Affected products

  • Cisco Asr 5000 Software: version 17.2.0 only; version 17.2.0.59184 only; version 17.3.1 only; version 17.7.0 only; version 18.0.0 only; version 18.0.0.57828 only; …

Published 2016-06-23. Last modified 2026-06-17.