CVE-2016-6401: Cisco Carrier Routing System

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494.

Affected products

  • Cisco Carrier Routing System: version 5.1.4 only; version 5.1_base only

Published 2016-09-17. Last modified 2026-06-17.