CVE-2015-0654
published 2015-03-13CVE-2015-0654: Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows…
PriorityP429high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
1.26%
66.3th percentile
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system | — | — |
| cisco | intrusion_prevention_system_mainapp_secure_socket_layer | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
vendor_cisco7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Intrusion Prevention System MainApp Secure Socket Layer Denial of Service Vulnerability
vendor_cisco·2015-03-11·CVSS 7.1
CVE-2015-0654 [HIGH] CWE-362 Cisco Intrusion Prevention System MainApp Secure Socket Layer Denial of Service Vulnerability
Cisco Intrusion Prevention System MainApp Secure Socket Layer Denial of Service Vulnerability
The Cisco
Intrusion Prevention System (IPS) Software has a vulnerability within the SSL/TLS subsystem utilized by the web management interface which could allow an
unauthenticated, remote attacker to cause a denial of service (DoS)
condition.
Cisco has released software updates that address this vulnerability. This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150311-ips
Cisco
Cisco Intrusion Prevention System MainApp Secure Socket Layer Denial of Service Vulnerability
vendor_cisco
CVE-2015-0654 Cisco Intrusion Prevention System MainApp Secure Socket Layer Denial of Service Vulnerability
CVE-2015-0654: Cisco Intrusion Prevention System MainApp Secure Socket Layer Denial of Service Vulnerability
The Cisco Intrusion Prevention System (IPS) Software has a vulnerability within the SSL/TLS subsystem utilized by the web management interface which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150311-ips
CWE: CWE-362, CWE-362
Bug IDs: CSCuq40652, CSCuq40652
GHSA
GHSA-f86g-x5mj-qg95: Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7
ghsa_unreviewed·2022-05-17
CVE-2015-0654 [HIGH] CWE-362 GHSA-f86g-x5mj-qg95: Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7
Race condition in the TLS implementation in MainApp in the management interface in Cisco Intrusion Prevention System (IPS) Software before 7.3(3)E4 allows remote attackers to cause a denial of service (process hang) by establishing many HTTPS sessions, aka Bug ID CSCuq40652.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2015-03-13
Published