CVE-2015-0649
published 2015-03-26CVE-2015-0649: Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP)…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.12%
80.0th percentile
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jm7x-w2c2-x6qr: Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2015-0649 [HIGH] CWE-20 GHSA-jm7x-w2c2-x6qr: Cisco IOS 12
Cisco IOS 12.2, 12.4, 15.0, 15.2, and 15.3 allows remote attackers to cause a denial of service (device reload) via malformed Common Industrial Protocol (CIP) TCP packets, aka Bug ID CSCun63514.
Cisco
Multiple Vulnerabilities in Cisco IOS Software Common Industrial Protocol
vendor_cisco·2015-03-25·CVSS 7.8
CVE-2015-0647 [HIGH] CWE-399 Multiple Vulnerabilities in Cisco IOS Software Common Industrial Protocol
Multiple Vulnerabilities in Cisco IOS Software Common Industrial Protocol
The Cisco IOS Software implementation of the Common Industrial Protocol (CIP) feature contains the following vulnerabilities when processing crafted CIP packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition:
Cisco IOS Software UDP CIP Denial of Service Vulnerability
Cisco IOS Software TCP CIP Packet Memory Leak Vulnerability
Cisco IOS Software TCP CIP Denial of Service Vulnerability
These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the others.
Successful exploitation of any of these vulnerabilities could allow an unauthenticated, remote attacker to cause a reload of the forwardin
Cisco
Multiple Vulnerabilities in Cisco IOS Software Common Industrial Protocol
vendor_cisco
CVE-2015-0649 Multiple Vulnerabilities in Cisco IOS Software Common Industrial Protocol
CVE-2015-0649: Multiple Vulnerabilities in Cisco IOS Software Common Industrial Protocol
The Cisco IOS Software implementation of the Common Industrial Protocol (CIP) feature contains the following vulnerabilities when processing crafted CIP packets that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition: Cisco IOS Software UDP CIP Denial of Service Vulnerability Cisco IOS Software TCP CIP Packet Memory Leak Vulnerability Cisco IOS Software TCP CIP Denial of Service Vulnerability These vulnerabilities are independent of each other; a release that is affected by one of the vulnerabilities may not be affected by the others. Successful exploitation of any of these vulnerabilities could allow an unauthenticated, remote attacker to cause a reload of the
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-26
Published