CVE-2015-0592
published 2015-02-12CVE-2015-0592: The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.82%
76.5th percentile
The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers incorrect kernel-timer handling, aka Bug ID CSCuh25672.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.4\(2\)t3 | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Kernel Timer Vulnerability
vendor_cisco·2015-02-10·CVSS 7.8
CVE-2015-0592 [HIGH] CWE-399 Cisco IOS Software Kernel Timer Vulnerability
Cisco IOS Software Kernel Timer Vulnerability
A vulnerability in the kernel timers in Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of the affected device.
The vulnerability is due to improper management of kernel timers. An attacker could exploit this vulnerability by sending crafted traffic, causing updates to timers used by the Zone-Based Firewall feature.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted traffic to the targeted device. This access requirement may reduce the likelihood of a successful exploit.
GHSA
GHSA-3xh9-qqm6-f9gm: The Zone-Based Firewall implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-0592 [HIGH] GHSA-3xh9-qqm6-f9gm: The Zone-Based Firewall implementation in Cisco IOS 15
The Zone-Based Firewall implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers incorrect kernel-timer handling, aka Bug ID CSCuh25672.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0592http://tools.cisco.com/security/center/viewAlert.x?alertId=37416http://www.securitytracker.com/id/1031713https://exchange.xforce.ibmcloud.com/vulnerabilities/100758http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0592http://tools.cisco.com/security/center/viewAlert.x?alertId=37416http://www.securitytracker.com/id/1031713https://exchange.xforce.ibmcloud.com/vulnerabilities/100758
2015-02-12
Published