LiveActive security incident?Get immediate response
CVE Record

CVE-2016-9201: A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an un...

A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass traffic that should otherwise have been dropped based on the configuration. More Information: CSCuz21015. Known Affected Releases: 15.3(3)M3. Known Fixed Releases: 15.6(2)T0.1 15.6(2.0.1a)T0 15.6(2.19)T 15.6(3)M.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysis

Security readout for executives and security teams

This flaw could let traffic through Cisco IOS or IOS XE Zone-Based Firewall rules that were meant to block it. For an organization relying on those routers for segmentation or perimeter filtering, the business risk is loss of an expected security boundary. Exposure is limited to Cisco IOS or IOS XE devices using Zone-Based Firewall, especially release 15.3(3)M3 or other releases Cisco identifies in its advisory. Devices not using this feature are not shown as exposed by the provided sources. Prioritize remediation where Cisco routers enforce network boundaries. A bypass could undermine segmentation without needing authentication, but urgency should be based on actual ZBF deployment and whether affected releases are present. Mitigation focus: Review Cisco advisory cisco-sa-20161207-ios-zbf for exact affected trains.; Upgrade vulnerable devices to a Cisco-listed fixed release.; Prioritize devices enforcing perimeter, partner, or internal segmentation policy..

Prepared

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2016-9201 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/aCisco IOS and Cisco IOS XECisco IOS and Cisco IOS XEListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.