CVE-2016-6379: Cisco IOS

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record (IPDR) packets, aka Bug ID CSCuu35089.

Affected products

  • Cisco IOS: version 12.2(33)cx only; version 12.2(33)cy only; version 12.2(33)cy1 only; version 12.2(33)sch only; version 12.2(33)sch0a only; version 12.2(33)sch1 only; …
  • Cisco IOS XE: version 3.14.0s only; version 3.14.1s only; version 3.14.2s only; version 3.14.3s only; version 3.14.4s only; version 3.15.0s only; …

Published 2016-10-05. Last modified 2026-06-17.