CVE-2016-6378: Cisco IOS XE

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets that require NAT, aka Bug ID CSCuw85853.

Affected products

  • Cisco IOS XE: version 3.1.3s only; version 3.1.4as only; version 3.1.4s only; version 3.2.1s only; version 3.2.2s only; version 3.3.0s only; …

Published 2016-10-05. Last modified 2026-06-17.