CVE-2016-1436

The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager process restart) via a crafted GTPv1 packet, aka Bug ID CSCuz46198.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ciscoCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
ciscoasr_5000_software
17.2.0
ciscoasr_5000_software
17.2.0.59184
ciscoasr_5000_software
17.3.1
ciscoasr_5000_software
17.7.0
ciscoasr_5000_software
18.0.0
ciscoasr_5000_software
18.0.0.57828
ciscoasr_5000_software
18.0.0.59167
ciscoasr_5000_software
18.0.0.59211
ciscoasr_5000_software
18.0.l0.59219:l0.59219
ciscoasr_5000_software
18.1.0
ciscoasr_5000_software
18.1.0.59776
ciscoasr_5000_software
18.1.0.59780
ciscoasr_5000_software
18.1_base:_base
ciscoasr_5000_software
18.4.0
ciscoasr_5000_software
19.0.1
ciscoasr_5000_software
19.0.m0.60737:m0.60737
ciscoasr_5000_software
19.0.m0.60828:m0.60828
ciscoasr_5000_software
19.0.m0.61045:m0.61045
ciscoasr_5000_software
19.1.0
ciscoasr_5000_software
19.1.0.61559
ciscoasr_5000_software
19.2.0
ciscoasr_5000_software
19.3.0
𝑥
= Vulnerable software versions