← Vulnerability feed

Vulnerability record · CVE-2016-1453 · published 6 October 2016

CVE-2016-1453: Cisco nx-os memory buffer overflow vulnerability

Cisco · Nx Os

Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long parameters in a packet header, aka Bug ID CSCuy95701.

9.8 CVSS 3.1 Critical EPSS 8.1% · top 5.4% CWE-119 · Memory buffer overflow
9.8CVSS 3.1 base score, v2 10.0
8.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 and 7700 devices allows remote attackers to execute arbitrary code via long parameters in a packet header, aka Bug ID CSCuy95701.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-otv MitigationVendor Advisory
http://www.securityfocus.com/bid/93409 Not ApplicableThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036946 Not ApplicableThird Party AdvisoryVDB Entry
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20161005-otv MitigationVendor Advisory
http://www.securityfocus.com/bid/93409 Not ApplicableThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036946 Not ApplicableThird Party AdvisoryVDB Entry

Track CVE-2016-1453 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.7CVE-2024-20399Cisco NX-OS CLI command injection allows root command executionCisco NX-OS fails to properly validate arguments passed to specific configuration CLI commands, allowing OS command injection. An attacker who alread…KEVEPSS 4.3%analysed9.8CVE-2018-0310Cisco nx-os out-of-bounds read vulnerabilityA vulnerability in the Cisco Fabric Services component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacke…EPSS 4.1%9.8CVE-2018-0301Cisco nx-os improper input validation vulnerabilityA vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to craft a packet to the management int…EPSS 17%9.8CVE-2016-1341Cisco nx-os permissions and access controls vulnerabilityCisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to ga…EPSS 1.1%9.1CVE-2021-1361Cisco nx-os vulnerabilityA vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switche…EPSS 1.6%9.0CVE-2015-4235Cisco application policy infrastructure controller \(apic\) permissions and access controls vulnerabilityCisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with…EPSS 2.2%9.0CVE-2013-1179Cisco nx-os memory buffer overflow vulnerabilityMultiple buffer overflows in the (1) SNMP and (2) License Manager implementations in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and …EPSS 3.4%9.0CVE-2013-1180Cisco nx-os memory buffer overflow vulnerabilityBuffer overflow in the SNMP implementation in Cisco NX-OS on Nexus 7000 devices 4.x and 5.x before 5.2(5) and 6.x before 6.1(1) and MDS 9000 devices …EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2016-1453), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.