CVE-2016-6457
Summary
| CVE | CVE-2016-6457 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-11-19 03:03:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). More Information: CSCuy93241. Known Affected Releases: 11.2(2x) 11.2(3x) 11.3(1x) 11.3(2x) 12.0(1x). Known Fixed Releases: 11.2(2i) 11.2(2j) 11.2(3f) 11.2(3g) 11.2(3h) 11.2(3l) 11.3(0.236) 11.3(1j) 11.3(2i) 11.3(2j) 12.0(1r). |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.003610000 probability, percentile 0.582580000 (date 2026-05-10)
Problem Types: CWE-119 | unspecified
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 2.0 | [email protected] | Primary | 6.1 | AV:A/AC:L/Au:N/C:N/I:N/A:C |
CVSS v3.1 Breakdown
Attack Vector
AdjacentAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0 Breakdown
Access Vector
AdjacentAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:A/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cisco | Application Policy Infrastructure Controller | 1.2\(2\) | All | All | All |
| Application | Cisco | Application Policy Infrastructure Controller | 1.2\(3\) | All | All | All |
| Application | Cisco | Application Policy Infrastructure Controller | 1.3\(1\) | All | All | All |
| Application | Cisco | Application Policy Infrastructure Controller | 1.3\(2\) | All | All | All |
| Application | Cisco | Application Policy Infrastructure Controller | 2.0\(1\) | All | All | All |
| Hardware | Cisco | Nexus 92160yc-x | - | All | All | All |
| Hardware | Cisco | Nexus 92304qc | - | All | All | All |
| Hardware | Cisco | Nexus 9236c | - | All | All | All |
| Hardware | Cisco | Nexus 9272q | - | All | All | All |
| Hardware | Cisco | Nexus 93108tc-ex | - | All | All | All |
| Hardware | Cisco | Nexus 93120tx | - | All | All | All |
| Hardware | Cisco | Nexus 93128tx | - | All | All | All |
| Hardware | Cisco | Nexus 93180yc-ex | - | All | All | All |
| Hardware | Cisco | Nexus 9332pq | - | All | All | All |
| Hardware | Cisco | Nexus 9336pq Aci Spine | - | All | All | All |
| Hardware | Cisco | Nexus 9372px | - | All | All | All |
| Hardware | Cisco | Nexus 9372tx | - | All | All | All |
| Hardware | Cisco | Nexus 9396px | - | All | All | All |
| Hardware | Cisco | Nexus 9396tx | - | All | All | All |
| Hardware | Cisco | Nexus 9504 | - | All | All | All |
| Hardware | Cisco | Nexus 9508 | - | All | All | All |
| Hardware | Cisco | Nexus 9516 | - | All | All | All |
| Operating System | Cisco | Nx-os | 11.2\(2g\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.2\(2h\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.2\(2i\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.2\(3c\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.2\(3e\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.2\(3h\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.3\(1i\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.3\(2f\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.3\(2h\) | All | All | All |
| Operating System | Cisco | Nx-os | 11.3\(2i\) | All | All | All |
| Operating System | Cisco | Nx-os | 12.0\(1m\) | All | All | All |
| Operating System | Cisco | Nx-os | 12.0\(1n\) | All | All | All |
| Operating System | Cisco | Nx-os | 12.0\(1o\) | All | All | All |
| Operating System | Cisco | Nx-os | 12.0\(1p\) | All | All | All |
| Operating System | Cisco | Nx-os | 12.0\(1q\) | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Cisco Nexus 9000 Series Platform Leaf Switches For Application Centric Infrastructure ACI 11.22x Through 12.01x | affected Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) 11.2(2x) through 12.0(1x) | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Cisco Application Policy Infrastructure Controller CVE-2016-6457 Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | tools.cisco.com | Mitigation, Vendor Advisory |
| Cisco Application Policy Infrastructure Controller on Nexus 9000 Series Leaf Switches Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.