CVE-2016-9201: Cisco IOS

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass traffic that should otherwise have been dropped based on the configuration. More Information: CSCuz21015. Known Affected Releases: 15.3(3)M3. Known Fixed Releases: 15.6(2)T0.1 15.6(2.0.1a)T0 15.6(2.19)T 15.6(3)M.

Affected products

  • Cisco IOS: version 15.3(3)m3 only

Published 2016-12-14. Last modified 2026-06-17.