CVE-2015-0608
published 2015-02-12CVE-2015-0608: Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to…
PriorityP433high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.78%
75.9th percentile
Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCul48736.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | <= 15.4\(2\)t3 | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Measurement, Aggregation, and Correlation Engine Denial of Service Vulnerability
vendor_cisco·2015-02-11·CVSS 7.1
CVE-2015-0608 [HIGH] CWE-362 Cisco IOS Measurement, Aggregation, and Correlation Engine Denial of Service Vulnerability
Cisco IOS Measurement, Aggregation, and Correlation Engine Denial of Service Vulnerability
A vulnerability in the Measurement, Aggregation, and Correlation Engine (MACE) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to cause an affected device to reload.
The vulnerability is due to a race condition between process switching and Cisco Express Forwarding switching. An attacker could exploit this vulnerability by sending crafted traffic to an affected router.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted traffic to the targeted device. This access requirement may reduce the likelihood of a su
GHSA
GHSA-65rh-573h-vgw7: Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15
ghsa_unreviewed·2022-05-17
CVE-2015-0608 [HIGH] CWE-362 GHSA-65rh-573h-vgw7: Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15
Race condition in the Measurement, Aggregation, and Correlation Engine (MACE) implementation in Cisco IOS 15.4(2)T3 and earlier allows remote attackers to cause a denial of service (device reload) via crafted network traffic that triggers improper handling of the timing of process switching and Cisco Express Forwarding (CEF) switching, aka Bug ID CSCul48736.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0608http://tools.cisco.com/security/center/viewAlert.x?alertId=37421http://www.securityfocus.com/bid/72566http://www.securitytracker.com/id/1031731https://exchange.xforce.ibmcloud.com/vulnerabilities/100808http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2015-0608http://tools.cisco.com/security/center/viewAlert.x?alertId=37421http://www.securityfocus.com/bid/72566http://www.securitytracker.com/id/1031731https://exchange.xforce.ibmcloud.com/vulnerabilities/100808
2015-02-12
Published