CVE-2016-1459: Cisco IOS

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of service (device reload) via crafted attributes in a BGP message, aka Bug ID CSCuz21061.

Affected products

  • Cisco IOS: version 12.4(4)xc7 only; version 12.4(15)t17 only; version 12.4(19a) only; version 12.4(22)yb2 only; version 12.4(24)gc4 only; version 12.4(24)gc5 only; …
  • Cisco IOS XE: version 3.13.2s only; version 3.13.3s only; version 3.13.4s only; version 3.13.5s only; version 3.14.0s only; version 3.14.1s only; …

Published 2016-07-17. Last modified 2026-06-17.