CVE-2016-6414: Cisco IOS

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.

Affected products

  • Cisco IOS: version 15.6(1)t1 only

Published 2016-09-22. Last modified 2026-06-17.