{"api_version":"1","generated_at":"2026-07-23T20:05:57+00:00","cve":"CVE-2016-6273","urls":{"html":"https://cve.report/CVE-2016-6273","api":"https://cve.report/api/cve/CVE-2016-6273.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2016-6273","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2016-6273"},"summary":{"title":"CVE-2016-6273","description":"The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a '01 19' opcode.","state":"PUBLISHED","assigner":"mitre","published_at":"2016-10-07 14:59:05","updated_at":"2026-05-06 22:30:45"},"problem_types":["NVD-CWE-noinfo","n/a"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://support.citrix.com/article/CTX217430","name":"http://support.citrix.com/article/CTX217430","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Denial of Service Vulnerability in Citrix License Server","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/93450","name":"http://www.securityfocus.com/bid/93450","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix License Server CVE-2016-6273 Denial of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.tenable.com/security/research/tra-2016-29","name":"https://www.tenable.com/security/research/tra-2016-29","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[R2] Citrix License Server / Flexera FlexNet Publisher lmadmin.exe 2F Packet Handling Remote DoS - Research Advisory | Tenable Network Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1037008","name":"http://www.securitytracker.com/id/1037008","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Citrix License Server Unspecified Bug Lets Remote Users Cause the Target System to Crash - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2016-6273","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2016-6273","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2016","cve_id":"6273","vulnerable":"1","versionEndIncluding":"11.14.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"license_server","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2016","cve_id":"6273","vulnerable":"1","versionEndIncluding":"11.14.0.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"citrix","cpe5":"license_server_vpx","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2016","cve_id":"6273","cve":"CVE-2016-6273","epss":"0.016690000","percentile":"0.822190000","score_date":"2026-05-07","updated_at":"2026-05-08 00:14:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T01:22:20.808Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.tenable.com/security/research/tra-2016-29"},{"name":"1037008","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1037008"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.citrix.com/article/CTX217430"},{"name":"93450","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/93450"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2016-10-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a '01 19' opcode."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T09:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"https://www.tenable.com/security/research/tra-2016-29"},{"name":"1037008","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1037008"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.citrix.com/article/CTX217430"},{"name":"93450","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/93450"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2016-6273","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a '01 19' opcode."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://www.tenable.com/security/research/tra-2016-29","refsource":"MISC","url":"https://www.tenable.com/security/research/tra-2016-29"},{"name":"1037008","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1037008"},{"name":"http://support.citrix.com/article/CTX217430","refsource":"CONFIRM","url":"http://support.citrix.com/article/CTX217430"},{"name":"93450","refsource":"BID","url":"http://www.securityfocus.com/bid/93450"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2016-6273","datePublished":"2016-10-07T14:00:00.000Z","dateReserved":"2016-07-22T00:00:00.000Z","dateUpdated":"2024-08-06T01:22:20.808Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2016-10-07 14:59:05","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["NVD-CWE-noinfo","n/a"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:license_server:*:*:*:*:*:windows:*:*","versionEndIncluding":"11.14.0.0","matchCriteriaId":"6271F416-8ECE-491E-830D-38623FE955F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:citrix:license_server_vpx:*:*:*:*:*:*:*:*","versionEndIncluding":"11.14.0.0","matchCriteriaId":"6C7B0A35-7A61-4C4A-B9D7-CF874BCC473E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2016","CveId":"6273","Ordinal":"1","Title":"CVE-2016-6273","CVE":"CVE-2016-6273","Year":"2016"},"notes":[{"CveYear":"2016","CveId":"6273","Ordinal":"1","NoteData":"The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to cause a denial of service (crash) via a type 2F packet with a '01 19' opcode.","Type":"Description","Title":"CVE-2016-6273"},{"CveYear":"2016","CveId":"6273","Ordinal":"2","NoteData":"2016-10-07","Type":"Other","Title":"Published"},{"CveYear":"2016","CveId":"6273","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}