CVE-2016-1478: Cisco IOS

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.

Affected products

  • Cisco IOS: version 15.5(3)s3 only; version 15.6(1)s2 only; version 15.6(2)s1 only; version 15.6(2)t1 only

Published 2016-08-08. Last modified 2026-06-17.