CVE-2016-6355: Cisco IOS XR

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791.

Affected products

  • Cisco IOS XR: version 5.1.0 only; version 5.1.1 only; version 5.1.1.k9sec only; version 5.1.2 only; version 5.1.3 only; version 5.2.0 only; …

Published 2016-08-23. Last modified 2026-06-17.