CVE-2016-6391: Cisco IOS

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036.

Affected products

  • Cisco IOS: version 12.2(44)ex only; version 12.2(44)ex1 only; version 12.2(46)se only; version 12.2(46)se1 only; version 12.2(46)se2 only; version 12.2(50)se only; …

Published 2016-10-05. Last modified 2026-06-17.