CVE-2016-6438: Cisco IOS XE
Medium severity, CVSS 5.9. EPSS: 1.2% chance of exploitation in the next 30 days.
A vulnerability in Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, remote attacker to cause a configuration integrity change to the vty line configuration on an affected device. This vulnerability affects the following releases of Cisco IOS XE Software running on Cisco cBR-8 Converged Broadband Routers: All 3.16S releases, All 3.17S releases, Release 3.18.0S, Release 3.18.1S, Release 3.18.0SP. More Information: CSCuz62815. Known Affected Releases: 15.5(3)S2.9, 15.6(2)SP. Known Fixed Releases: 15.6(1.7)SP1, 16.4(0.183), 16.5(0.1).
Affected products
- Cisco IOS XE: version 3.16.0cs only; version 3.16.0s only; version 3.16.1as only; version 3.16.1s only; version 3.16.2as only; version 3.16.2bs only; …
Published 2016-10-27. Last modified 2026-06-17.